Back to skill

Security audit

Travel Manager

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only travel planning helper with no executable code, hidden access, persistence, or credential handling.

Reasonable to install as a planning aid. Verify visa, passport, vaccination, and entry requirements with official sources before travel, and avoid sharing passport numbers, health records, payment details, or account credentials unless you are intentionally using a separate trusted booking or document workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says to use the skill for broad needs like planning trips, managing itineraries, optimizing costs, and coordinating travel arrangements, but it does not define clear trigger constraints or exclusion conditions. This makes activation scope ambiguous and increases the chance of unintended invocation for ordinary travel conversations.

Vague Triggers

Low
Confidence
86% confidence
Finding
The example "Find the most cost-effective international travel route" is a natural, generic request that many users might say in ordinary conversation. Without additional scoping or exclusion guidance, it can function as a vague trigger for invoking the skill too broadly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.