Back to skill

Security audit

Travel Agent Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed travel-booking helper that uses email and BonBook’s website for expected flight booking, change, cancellation, and setup workflows.

Install only if you trust BonBook and are comfortable letting your agent send and read BonBook-related email. Review each itinerary, price, refund rule, change, cancellation, calendar sync, PII entry, and payment step yourself, and avoid putting passport numbers, card numbers, credentials, or unnecessary personal data into email.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill repeatedly claims that every action requires explicit human approval, but the operational steps allow the agent to proceed with substantive actions like searching, emailing booking/change/cancel requests, selecting offers, and navigating checkout flows without an approval checkpoint at each step. In a travel-booking context, this can lead to unauthorized itinerary changes, cancellations, or financial commitments based on ambiguous or stale consent, especially because the skill leverages broad email access and external web actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README promotes high-impact actions such as booking, changing, and cancelling flights, plus calendar sync, without warning users that personal data will be emailed to a third party or that the skill can take account-impacting actions on their behalf. In this context, the omission is security-relevant because users and downstream agents may invoke the skill without understanding the privacy, authorization, and transaction risks involved.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.