Back to skill

Security audit

spontaneous trip planner

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to collect travel-planning preferences for itinerary help, with usability concerns but no evidence of hidden, destructive, or credential-seeking behavior.

Install only if you are comfortable with a travel skill prompting for trip details when travel topics come up. Non-Chinese users should verify they can understand the questions before submitting itinerary details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description says it auto-triggers whenever users mention broad travel-related terms like travel, sightseeing, attractions, or itinerary planning. That scope is overly broad and can cause the tool to activate during ordinary conversation, leading to unnecessary collection of user trip preferences and unwanted tool use without clear intent. The mandatory popup collection step increases the risk because a false trigger immediately pushes users into structured data entry.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill content is written to require Chinese interaction and does not provide a language selection or consent mechanism. This can confuse users who are operating in another language, causing them to misunderstand the popup questions or unknowingly submit incorrect travel information, especially since the flow mandates structured input before proceeding.

Static analysis

No suspicious patterns detected.