Back to skill

Security audit

schedule-planner-cxf

Security checks for vulnerabilities and agentic risk

Overview

This travel-planning skill is coherent and disclosed, with live Tuniu queries requiring an API key and local itinerary file generation as expected for its purpose.

Install only if you are comfortable using a Tuniu API key and sending travel search details to Tuniu. Keep passenger identity, phone numbers, order IDs, and payment links out of inputs, run installs with scripts disabled as documented, and review generated local files before sharing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 2)May include surrounding context.

text
# 敏感信息 - 切勿上传到 Git
.env

# 依赖目录
node_modules/

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a specific travel-itinerary and price-comparison skill with constrained use cases. The supplied code instead acts as a general dispatcher: it accepts arbitrary server, tool, and params from JSON and forwards them to an external function/service. That is materially broader than the declared purpose, because the code chunk itself exposes a generic remote invocation capability rather than specifically implementing only travel itinerary planning, price comparison, or HTML/QR export. While the external Tuniu service may be travel-related, this code alone does not substantiate the claimed specific behaviors and instead reveals a more general integration surface than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk is focused on a single capability: validating parameters and calling a local tuniu-cli package to fetch flight, train, or hotel search results. This aligns partially with the declared price-comparison/search aspect, but several declared core features are absent: there is no itinerary construction logic, no local HTML export, and no QR code generation. The primary behavior shown is a constrained travel search wrapper around Tuniu, which is materially narrower than the declared end-user functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises end-user travel itinerary planning, transportation/hotel price comparison, and HTML itinerary generation. The actual code chunk is only a test script that checks whether a local Tuniu CLI/library can be resolved and reports success or failure. There is no evidence here of itinerary generation, travel search, price comparison, QR code creation, or user-facing planning workflows. While a test/helper script can be a supporting detail, this chunk by itself materially does not match the declared primary purpose, so it should be flagged as a mismatch for this supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared description presents a broader travel-planning tool with price comparison across flights, trains, and hotels plus itinerary HTML export and optional QR code generation. The supplied code only computes rough travel-time estimates and transport suggestions based on distance and trip purpose. It performs no pricing lookups, no hotel handling, no itinerary assembly, no HTML generation, and no QR code functionality. While the code is travel-related, its actual scope is much narrower and materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
依赖固定为 `qrcode@1.5.4` 和 `tuniu-cli@1.0.7`,传递依赖由 `package-lock.json` 锁定。`.npmrc` 同样禁用安装脚本,避免途牛 postinstall 自动向其他 agent 目录安装技能。安装需要访问官方 npm registry;运行时不会下载安装代码。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

npm ci --ignore-scripts

text

依赖固定为 `qrcode@1.5.4` 和 `tuniu-cli@1.0.7`,传递依赖由 `package-lock.json` 锁定。`.npmrc` 同样禁用安装脚本,避免途牛 postinstall 自动向其他 agent 目录安装技能。安装需要访问官方 npm registry;运行时不会下载安装代码。

实时查询用当前 Node 的绝对路径启动固定的本地 `tuniu-cli/dist/index.js`,缺失或版本不符即停止。子进程只收到 `TUNIU_API_KEY`、关闭服务发现的开关及 Windows 必需的 `SystemRoot`。不继承全量环境,不接收自定义 CLI 路径,不回退到全局安装。

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Including .npmrc in the published files can expose registry configuration, scoped registry URLs, auth settings, or other package-management secrets if the file contains tokens or internal endpoints. In a distributable skill package, this increases the risk of credential leakage and supply-chain misuse, especially because consumers may inspect or republish the artifact.

Content

Scanner excerpt · package.json (reported line 59)May include surrounding context.

json
"skill-card.md",
    "skills.json",
    "package-lock.json",
    ".npmrc"
  ],
  "dependencies": {
    "qrcode": "1.5.4",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/security.test.js (reported line 55)May include surrounding context.

js
});

test('URLs reject scripts, phishing, credentials, orders and redirects before QR encoding', async () => {
  for (const value of ['javascript:alert(1)', 'data:text/html,test', 'file:///etc/passwd', 'http://www.tuniu.com/',
    'https://www.tuniu.com.evil.test/', 'https://evil.test/', 'https://u:p@www.tuniu.com/',
    'https://www.tuniu.com:444/', 'https://m.tuniu.com/u/order', 'https://www.tuniu.com/?next=https://evil.test',
    'https://www.tuniu.com/#order', 'https://www.tuniu.com/" onload="x', 'https://www.tuniu.com\\@evil.test/', '']) {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill declares network and environment-variable use in prose, but does not provide an explicit machine-readable tool/permission scope such as allowed tools or permissions. That creates a governance gap: the agent platform may not be able to enforce least privilege, and users or reviewers cannot reliably tell what capabilities are intended versus what code may exercise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L13 明确写明 language 只能为 zh-CN 或 en,这属于自然语言层面的语言/locale 限制。文档没有说明这是区域合规要求,也没有提供更广泛的语言选择或明确的用户 opt-in 机制,因此符合语言/locale policy violation 的判定标准。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated document sets lang="zh-CN" and uses a Chinese-only title and UI labels, which forces a specific language/locale in the skill output. The file does not provide any user opt-in, language selection, or justification that this is a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code hard-codes language: 'zh-CN' in the generated mock trip data, which imposes a specific language/locale setting. Under the policy, locale constraints should offer user opt-in or be clearly justified as region-specific; neither is evident in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a travel-planning skill that compares flight/train/hotel prices and generates itinerary HTML with optional QR codes. This script only performs local distance-based transport suggestions and travel-time estimates from command-line inputs, with no code for price comparison, hotel handling, itinerary generation, HTML export, or QR code creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document declares lang="zh-CN", which fixes the content to a specific language/locale. Under the policy, locale-specific behavior should either offer user choice or be clearly justified as region-specific; this file provides no such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The JSON explicitly sets "language": "zh-CN", which indicates a fixed locale preference in natural-language/config content. There is no accompanying indication that the user can choose another language or that the skill is intentionally limited to a China-specific/regional use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This JSON plan uses only Chinese city names throughout, which indicates a language/locale assumption embedded in the skill data. For all file types, natural-language policy issues include forcing a specific language or locale without user opt-in, and this file provides no indication that the locale constraint is optional or justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

As a manifest file, this description should make activation scope clear. The phrase "Travel price queries, local itinerary HTML and optional public platform homepage QR pages" describes capabilities but does not specify concrete trigger phrases, exclusions, or narrow activation context, which can lead to overly broad matching for general travel requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The keyword list includes only Chinese terms for some invocation metadata alongside brand-specific terms, which may bias routing or discovery toward a specific language/locale without documenting user choice. There is no adjacent indication that the skill supports multiple languages or that Chinese-language matching is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all guidance in a single language and does not indicate that the skill is intentionally limited to Chinese-speaking users or a China-specific audience. Under the policy check, forcing one language without user opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire markdown file is written in Simplified Chinese and presents the guidance only in that language, with no indication that users can choose another language or locale. The policy explicitly calls out language or locale constraints as a natural-language violation when they are imposed without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The validation logic rejects any language except 'zh-CN' and 'en' via the natural-language error 'Unsupported page language.' This imposes a locale/language constraint in code without any visible explanation here that the skill is region-specific or that users are explicitly opting into this limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated HTML fixes the page language to English (lang="en") while also embedding bilingual English/Chinese UI text. This imposes a specific language/locale presentation without any user opt-in or configurability, which matches the policy-violation category for forced language behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/tuniu.js:63