T09 · Insecure Skill Coding Practices
- Location
README.md:29- Finding
Plaintext Ctrip Credentials Stored in Project Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Ctrip hotel-search skill has useful travel automation code, but it needs review because it handles account/API credentials insecurely, includes under-disclosed third-party search scripts, and overstates some live-search capability.
Install only if you are comfortable with an agent controlling a browser logged into your Ctrip account. Do not put real account passwords or API keys in project files; use environment variables or a secret manager, keep config files out of version control, and verify all hotel results directly on Ctrip before relying on them. Treat the MATON/Brave scripts and demo hotel recommendations as separate or non-live paths unless the publisher clearly documents them.
README.md:29Plaintext Ctrip Credentials Stored in Project Configuration
src/details.js:12Unvalidated Navigation to Page-Supplied URLs in an Authenticated Browser Context
api_key_config.py:1MATON API Key Encouraged to Be Stored Directly in Source Code
The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.
The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.
The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.
The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.
The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.
The Chinese-language description promises real Ctrip automation and live comparison, but the finding states the skill only outputs static demo data. Presenting demo or fabricated output as live third-party results can mislead users, conceal absent security controls, and hide the fact that no genuine platform interaction or privacy safeguards are in place.
The implementation materially differs from the declared skill purpose: instead of automating Ctrip hotel search and detail retrieval, it sends arbitrary queries to a third-party Brave search gateway. This is dangerous because users and orchestrators may grant permissions or trust based on the manifest, while the code actually exfiltrates user queries to an unrelated external service and may return irrelevant or manipulated results.
The document states the skill is completed even though the body says the primary search functionality is unavailable due to lack of access to Ctrip. This inconsistency can mislead operators into relying on the skill for automated browsing or hotel comparison when it can only provide manual instructions, creating integrity and trust issues in agent workflows.
The file claims the skill is complete and ready, while the document itself admits the core automated capability cannot access Ctrip and requires manual user action. This is dangerous because it misrepresents operational security and capability, which can cause downstream agents or users to trust, invoke, or deploy the skill under false assumptions.
This markdown file is natural-language documentation, and its content appears to require Chinese as the only operating/documentation language. Under the policy, forcing a specific language without user opt-in or a documented, justified locale scope is a violation.
The documentation instructs users to run npx playwright install without pinning an exact package version. If playwright is resolved from the network at execution time, users may install an unexpected or compromised version, creating a supply-chain risk in a workflow that already handles browser automation and likely user credentials.
The quick-start guide instructs users to place live Ctrip credentials directly into a local config.json file during setup, but the setup step does not prominently warn about plaintext secret storage, accidental commits, or file-sharing exposure. In the context of a browser automation skill that logs into a real consumer account, this increases the chance of credential compromise and downstream account misuse.
The skill description advertises automatic login and instructs users to store Ctrip credentials in config.json, but it does not prominently warn users about the security implications of automated credential use and local plaintext secret storage. This can lead users to expose account credentials or run the skill without understanding that it will authenticate to a third-party service on their behalf.
The README instructs users to run npx playwright without pinning a specific package version, which can cause execution of an unexpected or newly published package version at install time. In a skill that automates browser actions and handles account credentials, supply-chain drift increases risk because compromised or malicious upstream code could gain access to authentication context or local system data.
The skill advertises capabilities that inherently require network access and likely environment-based secrets or credentials, but the manifest does not declare any explicit tool scope or permissions. This creates an opaque trust boundary: reviewers and users cannot clearly see what external access the skill expects, which increases the risk of hidden data access or over-broad execution when the skill is installed or run.
Browser automation against a third-party travel site can expose search history, account activity, personal preferences, and potentially session data, yet the skill provides no privacy or account-activity warning. Given the claimed automation of a live user account, the absence of disclosure increases the chance of unintended data exposure or account actions that the user did not fully understand.
Browser automation against a third-party travel site can expose search history, account activity, personal preferences, and potentially session data, yet the skill provides no privacy or account-activity warning. Given the claimed automation of a live user account, the absence of disclosure increases the chance of unintended data exposure or account actions that the user did not fully understand.
The guide tells users to run npx playwright without pinning a specific version, which can fetch and execute whatever version is current at install time. In a skill that relies on browser automation and is intended for end users, this increases supply-chain risk and weakens reproducibility if a compromised or breaking upstream release is published.
The documentation instructs users to place their Ctrip account credentials into config.json with no warning about plaintext secret handling, file permissions, or exclusion from version control. Because this skill automates login to a real travel account, exposed credentials could enable account takeover, access to booking history and personal data, or unauthorized purchases.
The implementation materially differs from the advertised skill behavior: instead of Ctrip browser automation, login, hotel detail retrieval, and comparison analysis, it sends a generic query to a third-party search API. This is dangerous because users may grant trust, credentials, or permissions based on the manifest while the code performs unrelated external data access, creating a supply-chain and transparency risk even if the current code is not overtly malicious.
The hard-coded query content is in Chinese and the request explicitly sets search_lang=zh and country=CN. This creates a language/locale policy issue because the skill enforces a specific locale with no user opt-in or documented reason that it must be China-specific.
The code relies on an unrelated third-party API endpoint for its core behavior without that dependency being justified by the stated purpose. Hidden or unexplained outbound dependencies are risky because they can exfiltrate user queries and undermine expected trust boundaries, especially when the skill claims a different operational model.
The code requires a generic API credential from the environment for a service not justified by the stated Ctrip automation purpose. In a mismatched skill, undeclared credential use increases the risk of hidden external dependencies, unintended data sharing, and misuse of secrets under a misleading capability description.
The request parameters hard-code search_lang='zh' and country='CN', which imposes a specific language and locale on every search. This matches the policy category for language/locale constraints because the code does not offer user opt-in or explain a region-specific requirement.
This code extracts review author names, review text, ratings, and dates from the page, which is user-generated content and may implicate privacy expectations. Although the file logs that it is fetching reviews, there is no warning or disclosure that personal or user-authored data will be collected and returned.
No suspicious patterns detected.