Back to skill

Security audit

Travel Agent Skill

Security checks for vulnerabilities and agentic risk

Overview

This travel-booking skill is not malware, but it needs review because its payment and change workflows do not consistently require final approval for the exact transaction.

Review this skill before installing. It is appropriate only if you are comfortable giving an agent email send/read ability for BonBook messages and sharing travel details with BonBook. Keep payment entry and CVC verification human-controlled, and require explicit approval of the exact itinerary, passenger, restrictions, refund terms, fees, and final total before every booking, paid change, or cancellation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:140
Finding

Flight Purchase Workflow Does Not Require Explicit Per-Transaction Approval

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 140-142
Vulnerability Type: Missing mandatory authorization for a financial transaction
Risk Level: High

Vulnerable Instructions

text
6. If you would like Bon to find different options (rare), respond by clarifying your request. Otherwise, click 'Select' below an offer to bring up its checkout page.
7. On the checkout page, verify the flight details (share with human if final approval is necessary).
8. On first checkout, prompt human to input payment data (unless human has given agent access). Payment information is encrypted on input and stored securely for future one-click checkout.

Technical Analysis

The booking procedure treats final human approval as optional by stating that flight details should be shared with the human only “if final approval is necessary.” It also permits the agent to use payment information when the human has previously given the agent access.

Access to payment information is not equivalent to authorization for a specific purchase. A general delegation or previously stored payment method must not be interpreted as standing approval for arbitrary future transactions. This workflow therefore weakens the per-action authorization boundary declared elsewhere in the skill, including the require-explicit: true configuration and the claim that every action requires explicit human approval.

After receiving a flight request, the agent is instructed to select an offer and advance toward checkout without an unconditional approval checkpoint that binds the human to the exact itinerary, passenger, fare, restrictions, and total price. This can cause an agent to perform a materially different or unexpectedly expensive transaction while relying only on broad payment access or an ambiguous earlier request.

A related pattern appears in the flight-change workflow at skill.md:159-161, where final review is likewise conditional and the ...[truncated 2144 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit human approval immediately before every booking, paid change, or cancellation, regardless of whether the agent can access a stored payment method, card information, or CVC.
  2. Replace “share with human if final approval is necessary” with an unconditional instruction such as:
    text
    Stop and obtain explicit human approval for this exact transaction before continuing.
    
  3. Present an immutable confirmation summary containing:
    • Passenger identity
    • Origin and destination
    • Dates and flight numbers
    • Fare class and baggage terms
    • Refundability and change restrictions
    • Base fare, taxes, fees, and final total
    • Payment method identifier, limited to non-sensitive details
  4. Bind approval to the exact offer using an offer ID, quoted amount, and expiration time. If any material detail or price changes, invalidate the approval and request confirmation again.
  5. Treat general access to payment data as permission to populate fields only, not as authorization to submit a transaction.
  6. Require the human to perform the final purchase confirmation or introduce a separate, auditable approval token generated after the human reviews the transaction.
  7. Apply the same mandatory approval gate to the change workflow at skill.md:159-161, including explicit acceptance of fare differences and fees.
  8. Log the approved transaction summary and approval timestamp without recording card numbers, CVC values, or other sensitive authentication data.
  9. Add a maximum-price or maximum-fare-difference policy so the agent cannot proceed when a returned quote exceeds the amount explicitly approved by the human.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 65)May include surrounding context.

  1. WEBSITE CHANNEL (optional): Account setup and payment occur on bonbook.co website (not email). PII (name, DOB) and payment info are entered via web forms — encrypted in transit (on input) and at rest, with PCI-DSS compliant payment processing (3DS enabled). Form completion by agent requires explicit human approval.

This skill does NOT store, transmit, or access credentials.

text

## CONSENT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises account-impacting actions such as booking, changing, and cancelling flights, plus calendar synchronization, without any visible warning about sensitive data sharing, third-party email transmission, or the possibility of financial/account consequences. In this context, the skill asks agents to perform real-world actions over email, so missing consent and risk disclosures increase the chance of unintended purchases, itinerary changes, or privacy exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The booking instructions explicitly require the agent to compose requests "in logical, English sentences." This imposes a specific language choice on all users without offering an alternative or explaining a necessary locale constraint, which is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest scope is 'Find, book, and change flights for your human via email,' which implies flight search and itinerary modification. The README expands the advertised behavior to include 'One-email cancellation' and 'Calendar sync,' which are additional capabilities not reflected in the stated manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.