Back to skill

Security audit

PriceWin Hotel Search

Security checks across malware telemetry and agentic risk

Overview

This hotel-search skill is a narrowly scoped guide for using a PriceWin MCP hotel search tool, with no executable code or local persistence in the artifact.

Before installing, confirm you are comfortable using the PriceWin MCP server for hotel searches, since city, dates, guest count, and filters may be sent to that service and OTA sources. Also note that the skill hardcodes Vietnamese as the language parameter, so results or OTA pages may be localized unless the agent or server overrides it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The instructions require calling the tool with `language="vi"`, which forces a specific language/locale behavior. The file does not offer a user choice, opt-in, or justification for why Vietnamese is mandatory, so this is a natural-language policy violation under the locale/language rule.

Behavior Manipulation

Medium
Category
Prompt Injection
Content
4. Present results as soon as status == "partial" with hotels
5. Continue polling silently — refine if more arrive

**Never tell the user "loading/please wait" after 1-2 polls — that's premature.**

## 4th source: OpenTravel
Confidence
75% confidence
Finding
Never tell the user

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.