T05 · Unauthorized Access and Privilege Escalation
- Location
skill.md:140- Finding
Flight Purchase Workflow Does Not Require Explicit Per-Transaction Approval
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 140-142
Vulnerability Type: Missing mandatory authorization for a financial transaction
Risk Level: HighVulnerable Instructions
text 6. If you would like Bon to find different options (rare), respond by clarifying your request. Otherwise, click 'Select' below an offer to bring up its checkout page. 7. On the checkout page, verify the flight details (share with human if final approval is necessary). 8. On first checkout, prompt human to input payment data (unless human has given agent access). Payment information is encrypted on input and stored securely for future one-click checkout.Technical Analysis
The booking procedure treats final human approval as optional by stating that flight details should be shared with the human only “if final approval is necessary.” It also permits the agent to use payment information when the human has previously given the agent access.
Access to payment information is not equivalent to authorization for a specific purchase. A general delegation or previously stored payment method must not be interpreted as standing approval for arbitrary future transactions. This workflow therefore weakens the per-action authorization boundary declared elsewhere in the skill, including the
require-explicit: trueconfiguration and the claim that every action requires explicit human approval.After receiving a flight request, the agent is instructed to select an offer and advance toward checkout without an unconditional approval checkpoint that binds the human to the exact itinerary, passenger, fare, restrictions, and total price. This can cause an agent to perform a materially different or unexpectedly expensive transaction while relying only on broad payment access or an ambiguous earlier request.
A related pattern appears in the flight-change workflow at
skill.md:159-161, where final review is likewise conditional and the ...[truncated 2144 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit human approval immediately before every booking, paid change, or cancellation, regardless of whether the agent can access a stored payment method, card information, or CVC.
- Replace “share with human if final approval is necessary” with an unconditional instruction such as:
text Stop and obtain explicit human approval for this exact transaction before continuing. - Present an immutable confirmation summary containing:
- Passenger identity
- Origin and destination
- Dates and flight numbers
- Fare class and baggage terms
- Refundability and change restrictions
- Base fare, taxes, fees, and final total
- Payment method identifier, limited to non-sensitive details
- Bind approval to the exact offer using an offer ID, quoted amount, and expiration time. If any material detail or price changes, invalidate the approval and request confirmation again.
- Treat general access to payment data as permission to populate fields only, not as authorization to submit a transaction.
- Require the human to perform the final purchase confirmation or introduce a separate, auditable approval token generated after the human reviews the transaction.
- Apply the same mandatory approval gate to the change workflow at
skill.md:159-161, including explicit acceptance of fare differences and fees. - Log the approved transaction summary and approval timestamp without recording card numbers, CVC values, or other sensitive authentication data.
- Add a maximum-price or maximum-fare-difference policy so the agent cannot proceed when a returned quote exceeds the amount explicitly approved by the human.
