Security checks for vulnerabilities and agentic risk
Overview
The skill is a coherent hotel-search helper, but it ships a plaintext bearer token in its MCP configuration, which users should review before installing.
Install only if you are comfortable with the skill contacting the ai-go-hotel MCP server for hotel searches. The publisher should rotate and remove the embedded bearer token, replace it with per-user or platform-managed secrets, and clarify language behavior so responses follow the user's preferred locale.
A bearer token is embedded directly in a client configuration intended to be packaged and distributed with the skill. Bearer credentials authorize their holder without requiring proof of possession beyond presenting the token. Consequently, anyone who can download, inspect, clone, or otherwise access the skill can extract the token and use it outside the intended client.
The token is also referenced as a prefilled authorization header in SKILL.md and references/aigohotel-mcp-spec.md, confirming that the credential-bearing configuration is intentionally included in the package. The repository does not provide enough information to determine the token's exact server-side permissions or whether it remains active.
Attack Path
An attacker downloads, clones, or inspects the distributed skill package.
The attacker opens references/mcp-client-config.json.
The attacker extracts the plaintext bearer token from the Authorization header.
The attacker sends requests to https://mcp.aigohotel.com/mcp with the copied header.
If the credential is active, the service treats the attacker as the token owner and permits operations within the token's assigned privileges.
No local code execution or system compromise is required for exploitation.
Impact Assessment
An attacker may obtain unauthorized access to MCP operations granted to the exposed credential. Based on the documented interface,
...[truncated 569 chars]
Remediation
View remediation
Remediation Suggestions
Revoke the exposed token immediately and issue a replacement because removing it from the current package does not invalidate previously distributed copies.
Remove the bearer token from the configuration, repository history, release archives, examples, and registry packages.
Replace the hardcoded value with a documented runtime secret reference, such as an environment variable or platform-managed secret:
json
The skill description includes broad activation language such as general hotel discovery, planning, comparison, and booking support, which can cause the agent to invoke this skill in loosely related travel conversations. Over-broad routing increases the chance of unnecessary tool use, accidental disclosure of user travel details to the MCP backend, and user confusion when the skill activates without clear intent.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
The output template is hard-coded in Chinese, which can override or ignore the user's language preference and produce responses the user cannot easily verify. In a booking context, this raises safety and usability risk because pricing, cancellation terms, and next-step confirmations may be misunderstood or incorrectly approved.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding
This markdown file contains user-facing skill descriptions and examples predominantly in Chinese, but it does not indicate that the skill is region-specific or provide any opt-in or alternative language. Under the policy, forcing a specific language without user choice is a natural-language policy violation.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
91% confidence
Finding
Line L42 specifies language default zh_CN, which imposes a specific language/locale by default in the natural-language spec. The file does not indicate that users can choose a different language or that this locale default is required for a documented region-specific purpose.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
84% confidence
Finding
The markdown includes a single Chinese-language test query as the example interaction. This can imply the skill is expected to operate in Chinese only, but the document does not state that the skill is region- or language-specific or that users may choose another language.