Back to skill

Security audit

Domestic Flight Search

Security checks for vulnerabilities and agentic risk

Overview

The flight-search skill is mostly coherent, but its optional local web server is under-protected and can expose API quota use or local JSON file reads if reachable by others.

Install only if you are comfortable using your own Juhe API key and keeping the HTTP mode local and trusted. Prefer the CLI mode; if you run serve mode, bind it only to 127.0.0.1, do not expose the port to a network, and use a dedicated low-quota Juhe key that you can revoke.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/domestic_flight_service.py:114
Finding

API Credential Embedded in Request URL

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/domestic_flight_service.py:197
Finding

Unauthenticated HTTP Endpoint Permits Arbitrary Local JSON File Access and API Quota Use

Content
View full analysis
None: # noqa: N802 parsed = urlparse(self.path) if parsed.path == "/health": self.send_json(200, {"ok": True, "service": "domestic-flight-search"}) return if parsed.path != "/search": self.send_json(404, {"ok": False, "error": "not_found"}) return params = parse_qs(parsed.query, keep_blank_values=False) try: args = argparse.Namespace( origin=self.require_param(params, "from"), destination=self.require_param(params, "to"), date=self.require_param(params, "date"), limit=int(params.get("limit", ["10"])[0]), max_segments=int(params.get("max_segments", ["1"])[0]), flight_no=params.get("flight_no", [""])[0], timeout=int(params.get("timeout", ["20"])[0]), sample_response=params.get("sample_response", [N ...[truncated 3959 chars]
Remediation
View remediation
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
If the user wants a round trip, run two one-way queries.
   If `JUHE_FLIGHT_API_KEY` is missing, tell the user to apply for a Juhe key and configure it before retrying.

## Output Rules

- Sort results by lowest `ticket_price` first.
- Prefer up to 5 options unless the user asked for more.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a local Python script, requires an environment secret, reads local files for airport/city resolution, and performs outbound network calls, but the manifest does not declare an explicit tool scope or permissions boundary. That increases the chance the runtime grants broader-than-expected capabilities, making review, containment, and policy enforcement harder if the skill is modified or abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains multiple user-facing error and help strings only in Chinese, such as validation errors and API-key setup guidance. The skill does not offer user opt-in for language/locale selection, and the module description does not clearly justify that it is restricted to Chinese-language users despite being a domestic-flight tool.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_domestic_flight_service.py (reported line 18)May include surrounding context.

python
def run_command(*args: str) -> dict:
    completed = subprocess.run(
        [sys.executable, str(SCRIPT), *args],
        check=True,
        capture_output=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that the skill supports Chinese city names, airport names, and IATA codes, but the example prompts and overall description imply a Chinese-language interaction model without offering any language/locale choice. Under the policy rule, a skill that effectively constrains language/locale should document the constraint or present it as an explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This manifest-style JSON uses only Chinese-script city names as lookup keys throughout, which imposes a specific language/locale assumption in natural-language data. Because there is no accompanying indication of locale scope or user choice in the file, it can violate the policy against forcing a language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON sample includes natural-language response fields and labels in Chinese, such as the success reason and airline/airport names, with no indication that the skill supports locale selection or that Chinese output is intentional and constrained. For a general-purpose sample/provider response, this can reflect a language-policy issue because it implicitly fixes the user-visible locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.