Back to skill

Security audit

Atlas Flight Booking

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a flight-booking purpose, but it tells agents to automatically install and replace executable tooling from remote sources without a separate user approval step.

Review before installing. The booking workflow has sensible payment and passenger-data safeguards, but the skill can automatically install or replace local executable tooling from remote sources. Prefer installing uv and atlas-flight-booking yourself from sources you trust, or only use this skill in an environment where automatic tool installation is acceptable.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:32
Finding

Unverified Remote Installer Is Downloaded and Executed Directly

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

External CLI Package Is Force-Installed Without Artifact Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description says to use the skill whenever a user wants to search, compare, verify, choose seats, create and pay for an order, or check status, but it does not define clear trigger phrases, scope limits, or negative examples. This broad natural-language activation could overlap with ordinary travel-planning requests and makes it unclear when this skill should activate versus a general travel assistant.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to install or upgrade tooling automatically and to avoid asking the user for permission, which authorizes autonomous system modification. In an agent environment, silently fetching installers, changing PATH-adjacent tooling, and continuing execution materially increases the risk of unintended software installation, supply-chain compromise, and execution in a context the user did not clearly approve.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
- macOS or Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`; use `wget -qO- https://astral.sh/uv/install.sh | sh` only when `curl` is unavailable.
- Windows: `powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"`.

Use the newly installed executable in the current session, including `$HOME/.local/bin/uv` on macOS/Linux or `$HOME\.local\bin\uv.exe` on Windows when `uv` is not yet on `PATH`. Run exactly `uv tool install --force --python 3.12 atlas-flight-booking==0.3.12`, using that resolved executable path when the CLI is missing, invalid, or older than the minimum supported version. If `atlas-flight` is not yet on `PATH`, resolve the tool binary directory with `uv tool dir --bin` and invoke `atlas-flight` from there; do not ask the user to restart the terminal. Verify that `atlas-flight --version` now reports `0.3.12` or newer and continue. Only stop when the automatic installation or upgrade actually fails; then give one concise failure explanation and the official `https://docs.astral.sh/uv/getting-started/installation/` link. Do not fall back to another Python environment or package manager.

Then run `atlas-flight auth status --json`. Retain `data.ticketing_activation_url` and `data.ticketing_blocker` only when returned; never invent or derive either field. If authorization is required, follow `references/cli-contract.md`. Explain that Atlas authorization is required before the interrupted task can continue and present the returned URL as a descriptive clickable link. Briefly explain what the user will do on the page: sign in and authorize with an existing ATRIP account, or choose **Create one**, finish registration, then sign in and authorize. Ask the user to return to the conversation and reply after authorization is complete. Stop the current turn without polling. After the user confirms completion, poll once for at most 120 seconds and resume the interrupted task only after `AUTHORIZED`.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'use this Chinese wording' imposes a specific language for a user-facing response path, even though policy requires avoiding forced language or locale constraints without user opt-in. Unlike line 12, which respects the user's language, this section requires Chinese output for a particular case regardless of the user's preference.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/passenger-input.md (reported line 5)May include surrounding context.

md
## Collection rule

Use the verification response as the source of truth. Ask only for fields listed in `data.requirements.required_fields`. Carry each `traveler_id` and `passenger_type` from `data.travelers`; never ask the user to invent IDs. Ask only for missing values, then build the payload for the user.

The order envelope also requires a contact name. Ask for it only if it is not already available from the passenger details. Contact email and mobile are optional unless the user supplies them.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

This variant uses wget to stream a remote installer directly into the shell, creating the same arbitrary-code-execution risk as curl|sh. Because the skill also pairs this with instructions to proceed automatically, the danger is amplified in agentic contexts where a user may not see or understand the installation step before execution.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
If `uv` is unavailable, detect the operating system and run the applicable official standalone installer:

- macOS or Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`; use `wget -qO- https://astral.sh/uv/install.sh | sh` only when `curl` is unavailable.
- Windows: `powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"`.

Use the newly installed executable in the current session, including `$HOME/.local/bin/uv` on macOS/Linux or `$HOME\.local\bin\uv.exe` on Windows when `uv` is not yet on `PATH`. Run exactly `uv tool install --force --python 3.12 atlas-flight-booking==0.3.12`, using that resolved executable path when the CLI is missing, invalid, or older than the minimum supported version. If `atlas-flight` is not yet on `PATH`, resolve the tool binary directory with `uv tool dir --bin` and invoke `atlas-flight` from there; do not ask the user to restart the terminal. Verify that `atlas-flight --version` now reports `0.3.12` or newer and continue. Only stop when the automatic installation or upgrade actually fails; then give one concise failure explanation and the official `https://docs.astral.sh/uv/getting-started/installation/` link. Do not fall back to another Python environment or package manager.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

This variant uses wget to stream a remote installer directly into the shell, creating the same arbitrary-code-execution risk as curl|sh. Because the skill also pairs this with instructions to proceed automatically, the danger is amplified in agentic contexts where a user may not see or understand the installation step before execution.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
If `uv` is unavailable, detect the operating system and run the applicable official standalone installer:

- macOS or Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`; use `wget -qO- https://astral.sh/uv/install.sh | sh` only when `curl` is unavailable.
- Windows: `powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"`.

Use the newly installed executable in the current session, including `$HOME/.local/bin/uv` on macOS/Linux or `$HOME\.local\bin\uv.exe` on Windows when `uv` is not yet on `PATH`. Run exactly `uv tool install --force --python 3.12 atlas-flight-booking==0.3.12`, using that resolved executable path when the CLI is missing, invalid, or older than the minimum supported version. If `atlas-flight` is not yet on `PATH`, resolve the tool binary directory with `uv tool dir --bin` and invoke `atlas-flight` from there; do not ask the user to restart the terminal. Verify that `atlas-flight --version` now reports `0.3.12` or newer and continue. Only stop when the automatic installation or upgrade actually fails; then give one concise failure explanation and the official `https://docs.astral.sh/uv/getting-started/installation/` link. Do not fall back to another Python environment or package manager.

Static analysis

No suspicious patterns detected.