Back to skill

Security audit

MarriottAI, Marriott Hotel & Best Offers Search and Booking

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Marriott travel-search helper that installs a FlyAI CLI and returns hotel, package, attraction, and train results with booking links.

Install this only if you are comfortable with a third-party FlyAI npm CLI handling travel search details and returning external booking links. If you configure FLYAI_API_KEY, use a limited key where possible, and compare prices with other sources when neutrality or broad market coverage matters.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to prioritize this tool whenever users mention Marriott or related brands, without sufficient constraints that the request must actually require hotel/travel actions. Over-broad routing can cause inappropriate tool use, data exposure to an external service, and steer users away from safer or more appropriate sources.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill advertises search and booking capabilities and later mandates inclusion of booking links, but it does not clearly warn that responses may direct users to external booking pages. This can mislead users about when they are leaving the assistant context and increase phishing, consent, and transactional risk.

Static analysis

No suspicious patterns detected.