Back to skill

Security audit

Ticket Price Compare

Security checks across malware telemetry and agentic risk

Overview

This travel-price skill is coherent and purpose-aligned, but live searches may share route and date details with travel providers.

Install this if you are comfortable with live travel searches sharing departure, destination, date, and possibly locale with booking or scraping providers. Leave optional API keys unset if you want reduced third-party exposure, and avoid using live lookup for sensitive travel plans.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README advertises very broad auto-trigger phrases such as ordinary travel-planning requests without defining clear boundaries, confirmation steps, or exclusions. In an agent skill context, this can cause the skill to activate on ambiguous user input and perform unintended networked lookups or data collection, increasing the risk of overreach and surprise behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is extremely broad, covering generic travel-shopping intents like finding cheap flights, train prices, deals, and booking platforms. In an agent ecosystem, this can cause the skill to activate for many ordinary travel requests and unnecessarily route user queries into a workflow that performs external lookups and scraping, increasing the chance of over-collection and unintended third-party data disclosure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends itinerary details such as origin, destination, date, and possibly locale to multiple third-party services including Ctrip, 12306, Firecrawl, Kiwi, and Amadeus, but it does not clearly disclose this data sharing to users before use. This is dangerous because even seemingly routine travel queries can reveal sensitive personal plans, and routing them through several providers expands privacy, tracking, and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.