Back to skill

Security audit

Travel Income Idea

Security checks for vulnerabilities and agentic risk

Overview

The skill is a travel-income idea assistant, but its package also includes instructions for database/source-code changes and legally sensitive monetization tactics that need review before use.

Install only if you intend to review a Chinese-language hackathon/demo skill and will keep it in a controlled environment. Do not run the database injection, backend-console, or code-modification instructions unless you are authorized for that exact demo system and have a rollback plan. Treat advice about ticket resale, venue selling, duty-free proxy buying, deposits, customer contact details, and photo uploads as compliance-sensitive and verify local law, platform rules, privacy consent, and tax/customs obligations first. Redact internal account details, local paths, and private URLs before redistribution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (55)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is supposed to help users discover travel income ideas, but this document instructs an agent to perform bulk database writes, modify frontend source files, and implement new product features. That is dangerous because it materially expands scope from advisory behavior into privileged operational changes, creating a path for unauthorized persistence, data corruption, and codebase modification if the agent follows embedded instructions automatically.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill’s documented workflow goes far beyond its stated purpose of suggesting travel-income ideas and instructs an operator to seed a database, modify source code, and deploy application changes. This creates a capability-expansion risk where a conversational/content skill becomes an operational change agent with write access to persistent data and the codebase, increasing the chance of unauthorized or unsafe modifications.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The document expands the skill from generating travel-income ideas into end-to-end booking support and platform redirection, which materially increases the skill’s capability beyond its declared purpose. This scope expansion can enable unintended handling of travel planning and purchasing flows, increasing risk around user data use, misleading automation boundaries, and unsafe downstream actions.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
Integrating flight, train, and hotel APIs introduces third-party action and data-exchange capabilities unrelated to a travel-income idea discovery skill. Even if framed as convenience, this broadens the trust boundary and may expose itinerary inputs, preferences, and user behavior to external providers without a scope-appropriate need.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is supposed to help users discover travel-income ideas, but this document instructs an agent to perform bulk database population, SQL/script generation, execution, and post-write verification. That materially expands the skill from advisory behavior into privileged data-modification actions, increasing the chance of unauthorized writes, corruption of production data, and misuse of connected backend capabilities.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The documented behavior adds trip-booking, external search, and outbound booking-link generation, which is outside the stated purpose of recommending travel-income ideas. This broadens the agent's authority to perform networked actions and influence transactional flows, creating unnecessary exposure to data sharing, phishing/open-redirect style issues, and unintended third-party interactions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The community case presents duty-free proxy shopping/代购 as a successful monetization tactic without any warning about customs rules, resale restrictions, tax obligations, platform policy violations, or counterfeit/liability concerns. Because the skill is designed to suggest travel-income schemes, this omission may steer users toward legally risky conduct under the appearance of a vetted recommendation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The AI tools page explicitly encourages users to include customer-facing contact details and upload/share photos for promotional materials, but provides no privacy, consent, or data-handling safeguards. In this skill’s context, that omission can normalize collecting, publishing, or reusing personal data and images without informed consent, creating privacy, harassment, and compliance risks.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The README explicitly frames '信息差变现' methods such as ticket scalping, proxy booking, and price arbitrage as supported monetization strategies. In a travel-income assistant context, this goes beyond benign trip planning and normalizes workflows that may violate venue rules, platform terms, consumer-protection rules, or local laws, increasing the chance the skill facilitates illicit resale behavior.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill description markets potentially unlawful resale and proxy-purchase schemes as standard options without sufficiently prominent guardrails, disallowed-use boundaries, or enforcement risk disclosures. Because the product's core value proposition is helping financially stressed users monetize travel, the context increases the likelihood users will act on risky or noncompliant suggestions.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The concert example provides step-by-step operational guidance for sourcing merchandise, scouting vending locations, posting sales ads, collecting payments, and moving to alternate areas if venue enforcement blocks sales. That level of procedural detail materially assists unauthorized street vending and evasion of venue restrictions, making the skill more dangerous than a generic discussion of risks.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The Hainan duty-free example promotes a concrete resale workflow: advertising in social groups, taking deposits, optimizing a shopping list around duty-free offers, purchasing goods, and shipping them to customers. Even though it mentions quotas and customs compliance, the overall design still facilitates gray-market proxy buying and resale that may breach customs, tax, platform, or resale regulations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list is broad and loosely scoped, so the skill may activate for ordinary discussion about travel, side income, or adjacent topics without clear user intent to use this specific workflow. In an agent environment, over-broad triggering can cause inappropriate invocation, unnecessary data gathering or planning, and increase the chance of surfacing risky monetization guidance such as gray-market resale or proxy shopping when the user did not explicitly request it.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The document exposes an internal corporate account identifier and internal operational URLs that are unrelated to the skill's user-facing purpose. Even if intended as a deployment report, embedding these details in the skill package increases the risk of internal system enumeration, phishing targeting, and unauthorized discovery of management surfaces.

Ssd 3

Medium
Confidence
97% confidence
Finding
Publishing a specific internal corporate email/account in plain text leaks personally identifiable operational information and creates a targeting vector for phishing, impersonation, and internal reconnaissance. In a shared operational document bundled with the skill, this disclosure is unnecessary to the product's functionality and therefore avoidable.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The file instructs users to log into a separate backend and execute a data injection workflow, which is outside the declared advisory scope of a travel-income suggestion skill. This can facilitate unintended modification of demo or system data and broadens the operational attack surface by normalizing privileged backend actions for users.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document describes a data injection step without warning about its effect on demo or system state, which can mislead users into performing potentially destructive or unauthorized actions. Lack of safety context is especially risky because the skill itself does not need end users to manipulate backend data to receive travel-income advice.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords include short, common travel-income phrases that can plausibly appear in broad user conversations, increasing the chance of unintended skill activation. In this skill’s context, accidental activation is more concerning because the skill discusses potentially sensitive or compliance-heavy activities such as resale,代购, and venue-adjacent selling, which could surface risky guidance to users who did not explicitly request it.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger questions are broad and lack scope constraints, so ordinary questions about budget travel or side jobs could activate the skill even when the user is not asking for this specific workflow. Because the skill may recommend borderline regulated activities like ticket resale or duty-free purchasing, ambiguous activation can expose users to inappropriate or risky suggestions without clear consent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata presents its description entirely in Chinese, which indicates a fixed language/locale expectation but provides no opt-in or alternative language choice. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
These instructions tell an agent to bulk insert 100 records into a database and update application files, but they do not present clear warnings that the actions modify persistent data and source code. In skill context, that is risky because users may trigger what appears to be a content-generation helper while actually authorizing destructive or irreversible backend and frontend changes.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The added travel-booking/search workflow is unrelated to the stated skill purpose of finding ways to earn money while traveling. Introducing flight/train/hotel search, Tavily lookups, and booking-link generation broadens the attack surface to external services and user travel data, increasing the chance of privacy leakage, unsafe redirects, or unauthorized third-party interactions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The booking feature section directs external API/search usage and one-click booking link generation without notifying users about third-party service access, data exposure, or redirection risks. In this skill's context, those instructions are out of scope and could lead to silent transmission of itinerary details or unsafe links under the guise of a travel-income assistant.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The template instructs users to publicly share direct contact details and a local filesystem path, which can leak personally identifiable information and internal environment details. Even though this is not executable code, exposing corporate email, chat ID, and workstation paths can enable phishing, social engineering, and unnecessary disclosure of internal system structure.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The guide substantially expands the skill from idea discovery into operational database seeding, frontend modification, and booking-feature implementation. This creates a scope gap where an agent may be induced to perform privileged repository and data mutations unrelated to the declared skill purpose, increasing the chance of unintended or unsafe changes.

Static analysis

No suspicious patterns detected.