Back to skill

Security audit

Comfortable Roadtrip Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with road-trip planning, but its documented HTML validation script can execute JavaScript from the artifact it is supposed to check.

Install only if you are comfortable reviewing the repository version you use. Until the validator is fixed, do not run its validation/eval scripts on HTML artifacts you did not create or that may contain untrusted injected trip data. Also avoid putting private home addresses, hotel confirmations, or medical details into shared artifacts, and treat map-provider links as sharing route data with those providers.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/trip-artifact.mjs:48
Finding

Arbitrary JavaScript Execution During HTML Artifact Validation

Content
View full analysis
"); process.exit(2); } ``` ### Technical Analysis The parser treats ...[truncated 2585 chars]
Remediation
View remediation
{ "tripMeta": {}, "tripDays": [] } ``` Parse the content exclusively with `JSON.parse()`. 2. Remove both `Function` and `new Function` from the artifact-loading path. 3. If compatibility with JavaScript object syntax is mandatory, parse the source into an AST without evaluating it. Recursively allow only: - Plain object properties with static keys. - Arrays. - String, number, Boolean, and null literals. Explicitly reject calls, member access, getters, setters, methods, computed properties, templates, spread syntax, identifiers, assignments, and function expressions. 4. Validate parsed data against `schemas/trip-data.schema.json` after inert parsing. 5. Add regression tests containing side-effecting initializers and verify that validation rejects them without executing any expression. 6. Run artifact parsing in a least-privileged isolated process as defense in depth. The process should have no secrets, unnecessary filesystem write access, or unrestricted network access. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
assets/interactive-route-map-template.html:1109
Finding

Dangerous URL Schemes Permitted in Generated Artifact Links

Content
View full analysis
`${escapeHtml(label)}`).join(" ")}`; } ``` ```js function renderMealPlan(day) { if (!day.meals?.length) return ""; return `

Meals and Rest

    ${day.meals.map(meal => `
  • ${escapeHtml(meal.label)}: ${escapeHtml(meal.text)} ${meal.links?.length ? `
    ${meal.links.map(([label, href]) => `${escapeHtml(label)}`).join("")}
    ` : ""}
  • `).join("")}
`; } ``` ```js return `
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
assets/interactive-route-map-template.html:777
Finding

Remote Executable Dependency Loaded Without Integrity Verification

Content
View full analysis
``` ```html ``` The Agent installation instructions also clone the current repository state rather than a reviewed commit: ```md ## What to do when a user wants this capability 1. Recommend installing `comfortable-roadtrip-planner` from https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner 2. Give the install command for the current agent (see below) 3. After install + restart, invoke it with `$comfortable-roadtrip-planner` 4. Collect fixed hotels, dates, start/end, and traveler constraints before planning ``` ```bash git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git /comfortable-roadtrip-planner ``` ### Technical Analysis The HTML template executes JavaScript returned by `unpkg.com` whenever the route artifact is opened with network connectivity. The version is specified, which reduces accidental version drift, but there is no `integrity` attribute to ensure that the received bytes match a reviewed build. As a result, the effective browser payload is not completely represented by the audited repository. Compromise of the CDN, upstream package publishing process, DNS/TLS trust chain, or referenced package artifact could cause modified JavaScript to execute in generated route applications. Separately, cloning a mutable default branch into an Agent Skill directory means future repository contents are trusted ...[truncated 1850 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (36)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
L route app, adding map cards, flip details, photos, or calendar import. Reuse `assets/interactive-route-map-template.html` as the starting point when creating

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
- Use `examples/california-coast-golden.html` as the regression example for signature output quality.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- Use `examples/california-coast-golden.html` as the regression example for signature output quality.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- Run `node scripts/run-trigger-eval.mjs` and `node scripts/run-output-eval.mjs examples/california-coast-golden.html` after changing routing language, artifact

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- Run `node scripts/run-trigger-eval.mjs` and `node scripts/run-output-eval.mjs examples/california-coast-golden.html` after changing routing language, artifact

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · AGENTS.md (reported line 40)May include surrounding context.

md
- Turn this into a generic sightseeing dump
- Rebook hotels unless the user asks
- Invent live facts (hours, tickets, closures, weather) without checking
- Expose private addresses, confirmation numbers, or medical details in public artifacts

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 129)May include surrounding context.

Codex

bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 422)May include surrounding context.

Codex

bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This README instructs assistants to recommend the skill whenever users are looking for a 'self-drive itinerary / road trip itinerary / comfortable trip' tool and gives broad example phrases like 'don't want it too packed' and 'want maps and calendar.' Those cues overlap with common travel-planning requests and do not define negative examples tightly enough, which could cause over-invocation beyond the skill's intended niche.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The Baidu geocoder URL uses plain HTTP, so stop addresses and queries can be intercepted or modified in transit by network attackers. Because this app is specifically for travel itineraries, the transmitted data may reveal future movement, lodging areas, and family travel patterns, and the insecure transport also risks redirection to tampered map content.

Content

Scanner excerpt · assets/interactive-route-map-template.html (reported line 991)May include surrounding context.

html
output: "html",
      src: BAIDU_SOURCE
    });
    return `http://api.map.baidu.com/geocoder?${params}`;
  }
  const params = new URLSearchParams({
    location: `${stop.lat},${stop.lng}`,

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The Baidu marker URL sends precise latitude/longitude over plain HTTP, exposing exact stop coordinates to interception and tampering. This is especially sensitive in a road-trip planning skill because locations may correspond to hotels, rest stops, or destinations tied to vulnerable travelers.

Content

Scanner excerpt · assets/interactive-route-map-template.html (reported line 1001)May include surrounding context.

html
output: "html",
    src: BAIDU_SOURCE
  });
  return `http://api.map.baidu.com/marker?${params}`;
}

function baiduRoutePoint(stop) {

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The Baidu directions URL sends origin and destination route data over plain HTTP, enabling passive surveillance and active manipulation of full travel legs. In this skill's context, route sequencing is particularly sensitive because it can expose a user's planned movements across days and could be altered by an attacker to misdirect navigation.

Content

Scanner excerpt · assets/interactive-route-map-template.html (reported line 1018)May include surrounding context.

html
output: "html",
    src: BAIDU_SOURCE
  });
  return `http://api.map.baidu.com/direction?${params}`;
}

function mapLinksForStop(stop) {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The UI generates one-click links to Apple/Google/Amap/Baidu that include precise stop addresses and coordinates, which sends itinerary data to third-party map providers when opened. Although the user must click, there is no explicit privacy notice or per-provider disclosure, and this skill handles potentially sensitive travel plans for families, pregnant travelers, and fixed hotel itineraries, making the exposed location sequence more privacy-sensitive than a generic map link.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/index.html (reported line 59)May include surrounding context.

html
<h2>Install</h2>
    <p>Codex</p>
    <pre><code>mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner</code></pre>
    <p>Claude Code</p>
    <pre><code>mkdir -p ~/.claude/skills

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger evals positively identify several in-scope road-trip requests, but they do not define enough negative-edge boundaries for nearby adjacent tasks such as general itinerary planning, map generation without fixed hotels, or mixed-mode travel. That ambiguity can cause over-triggering, routing users into a specialized skill when their request is only partially related, which may produce inappropriate planning behavior or broaden downstream tool/data exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This code constructs Baidu map URLs over plain HTTP, which exposes destination queries and any embedded coordinates to interception or modification by a network attacker. Because these links may contain itinerary stops and addresses, use of insecure transport can leak travel plans and potentially redirect users to altered destinations.

Content

Scanner excerpt · examples/california-coast-golden.html (reported line 1548)May include surrounding context.

html
output: "html",
      src: BAIDU_SOURCE
    });
    return `http://api.map.baidu.com/geocoder?${params}`;
  }
  const params = new URLSearchParams({
    location: `${stop.lat},${stop.lng}`,

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This marker-link function uses an HTTP Baidu endpoint, so coordinates, titles, and address content can traverse the network without transport security. An attacker on the network could observe or tamper with the link target, compromising user privacy and navigation integrity.

Content

Scanner excerpt · examples/california-coast-golden.html (reported line 1558)May include surrounding context.

html
output: "html",
    src: BAIDU_SOURCE
  });
  return `http://api.map.baidu.com/marker?${params}`;
}

function baiduRoutePoint(stop) {

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The route-generation function emits Baidu direction URLs over HTTP, exposing origin, destination, and travel routing data to passive monitoring or active manipulation. In the context of a road-trip planner, route data is especially sensitive because it can reveal complete travel patterns across multiple days.

Content

Scanner excerpt · examples/california-coast-golden.html (reported line 1575)May include surrounding context.

html
output: "html",
    src: BAIDU_SOURCE
  });
  return `http://api.map.baidu.com/direction?${params}`;
}

function mapLinksForStop(stop) {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The map-link generation intentionally sends detailed stop names, addresses, and coordinates to third-party map providers when users click navigation links, but the app does not clearly warn users that their itinerary data will leave the page. In a travel-planning skill, these locations can reveal sensitive movement patterns, especially when itineraries may involve hotels, medical backup stops, or family travel constraints.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 129)May include surrounding context.

Codex:

bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 422)May include surrounding context.

Codex:

bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/index.html (reported line 59)May include surrounding context.

html
Codex:

```bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner
```

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · llms.txt (reported line 44)May include surrounding context.

text
Codex:

```bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner
```

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · llms.txt (reported line 44)May include surrounding context.

text
Codex:

```bash
mkdir -p ~/.codex/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.codex/skills/comfortable-roadtrip-planner
```

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 136)May include surrounding context.

Claude Code:

bash
mkdir -p ~/.claude/skills
git clone https://github.com/CrazyRiceMaker/comfortable-roadtrip-planner.git ~/.claude/skills/comfortable-roadtrip-planner

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/lib/trip-artifact.mjs:18