Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs operators to disable TLS certificate verification via NODE_TLS_REJECT_UNAUTHORIZED=0 for networked travel queries. This enables man-in-the-middle interception or tampering with hotel, POI, and flight responses, which is dangerous because the skill handles externally sourced travel data that users may trust for purchases or planning.
