Back to skill

Security audit

China Tour

Security checks across malware telemetry and agentic risk

Overview

This tour-guide skill mostly matches its stated purpose, but it needs review because it can send users' questions and conversation history to an under-disclosed HTTP backend.

Install only if you are comfortable with a tour skill that may use a remote backend for answers. Avoid sharing sensitive travel, family, or location details unless the publisher documents the backend, uses HTTPS, explains retention, and makes remote use optional; also treat physical safety and politically sensitive narration as content that needs user judgment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The file explicitly recommends that users stand at a platform edge for a photo composition, which is unsafe in a travel guidance context where users may directly follow instructions in real physical environments. This is made more concerning by the same document acknowledging climbing and slip hazards, so the risky advice is both actionable and contextually inconsistent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example triggers are generic conversational phrases such as 'What's next?' and 'Best photo spots?' that can easily appear in unrelated chats. In an agent environment, overly broad activation phrases can cause unintended invocation, pulling the skill into contexts where it may access location, history, or other context without the user clearly intending to use this tour skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The Chinese activation guidance is similarly broad, using common phrases like '接下来去哪' and '这里有什么故事' without requiring explicit tour context. This increases the chance of accidental triggering during ordinary conversation, which can lead to unintended behavior and context exposure in multi-skill agent systems.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases include generic conversational prompts like 'What's next?' and '接下来去哪儿?', which are broad enough to match ordinary dialogue outside the intended tourism context. This can cause unintended activation, leading the skill to handle requests when the user did not mean to invoke it, potentially causing confusion or unnecessary data loading/API calls.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The profile collection template solicits personal trip-context data such as whether the user is alone, with children, or with elders, but does not tell users that answering is optional, how the data will be used, or whether it will be stored. In a travel-assistant context, this can normalize unnecessary collection of potentially sensitive contextual information and increase privacy risk, especially if logs are retained or shared with backend services.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The content presents politically sensitive claims about Tibet and governance as objective fact in a general-audience cultural guide, without attribution, neutrality, or acknowledging contested perspectives. In a bilingual tourism skill, this can create policy, trust, and localization risk by exposing users to one-sided political framing where they expect cultural and historical guidance.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This section uses one-sided phrasing about Tibet-China relations and related historical interpretation without neutrality or user choice. Because the file is intended for public-facing cultural narration, such wording can cause compliance issues, user harm, or reputational damage in different locales even if there is no traditional software exploit.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The modern history section describes the Fourteenth Dalai Lama using politically charged wording without attribution or neutral framing. In a tourism and cultural assistant, this increases the chance of biased output, policy violations, and user distrust, especially for international audiences encountering sensitive contemporary history.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The client sends user questions and optional conversation history to a remote backend API, and the code does not provide any built-in user-facing notice, consent flow, or redaction step before transmitting potentially sensitive content. In a tour-guide skill, users may share travel plans, location details, companions, or other personal context, so silent off-device transmission creates a real privacy risk even if the transport is functionally required.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.