Back to skill

Security audit

Travel Guide Test

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent, but it can publish travel details to Cloudflare Pages and ask for Cloudflare access information without a clear final confirmation or secret-handling boundary.

Install only if you want a skill that may turn travel plans into a public Cloudflare Pages site. Before deployment, confirm exactly what will be published, remove sensitive trip or family details, verify the Cloudflare project/account, and provide credentials only through a secure secret mechanism with minimal permissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description is broad enough to match many ordinary travel-planning requests, which can cause the skill to activate when the user did not intend website generation or external deployment workflows. In this skill’s context, that increases the chance of unnecessary data collection, persistence of travel preferences, and escalation into publishing actions beyond simple advice.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to deploy content publicly to Cloudflare Pages and request auth/token/account details, but it does not require an explicit user confirmation about public publication, exposure of itinerary details, or safe credential-handling boundaries. In a travel-planning context, published pages may contain sensitive trip timing, destinations, hotels, and family details, so silent progression into deployment or token collection creates meaningful privacy and security risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.