Back to skill

Security audit

rollinggo-hotel

Security checks for vulnerabilities and agentic risk

Overview

This hotel booking skill is purpose-aligned overall, but it installs and auto-updates mutable executable code and can create real bookings using personal data, so it needs human review before installation.

Install only if you trust RollingGo's npm and GitHub release channels and are comfortable with a persistent CLI that can log in, query prior orders, collect guest names and email, create real hotel orders, and return payment links. Require explicit approval before installing, updating, booking, or sending personal data, and avoid running it with administrator privileges.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.py:19
Finding

Unverified, Mutable Executables Are Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rgg.js:34
Finding

Windows Shell Invocation Allows Command Injection Through CLI Arguments

Content
View full analysis
`, `^`, `%`, `(`, and `)`. Relevant JavaScript code: ```javascript // 3. Escape arguments containing spaces for Windows cmd.exe function sanitizeArgs(args) { return args.map((arg) => { if (typeof arg === 'string' && arg.includes(' ') && !arg.startsWith('"')) { return `"${arg}"`; } return arg; }); } const { cmd, shell, fallbackCmd } = resolveExecutable(); function runChild(targetCmd, useShell) { const args = useShell ? sanitizeArgs(process.argv.slice(2)) : process.argv.slice(2); const child = spawn(targetCmd, args, { stdio: 'inherit', env: process.env, shell: useShell, }); ``` The Python fallback contains a similar pattern: ```python def main(): args = [target_cmd] + sys.argv[1:] try: use_shell = is_win and target_cmd.endswith(".cmd") res = subprocess.run(args, shell=use_shell) ``` The Skill constructs CLI parameters from user-controlled hotel requests, including the original query, place, hotel name, and guest information. If any such value reaches the Windows wrapper without strict validation, command processor syntax can be interpreted as a second command instead of as literal hotel data. Quoting only arguments containing spaces is not a safe command-line encoding algorithm. An injection payload does not require spaces, and quoted strings can still be unsafe when quote characters or expansion syntax are accepted. The use of `shell: true` is unnecessary for native executables and should be avoided for `.cmd` launchers wh ...[truncated 1377 chars]
Remediation
View remediation
`, `^`, `%`, quotes, parentheses, and newline characters, and verify that each value is delivered literally to the CLI. 8. Run the wrapper under a non-administrative account with a restricted environment and filesystem permissions to reduce impact if another command-construction defect is introduced. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a hotel booking assistant, but it also instructs the agent to install software globally, download binaries from releases, modify executable permissions, and execute local scripts. This mismatch hides materially more dangerous behavior than a user would reasonably expect from the declared purpose, increasing the risk of unsafe consent and covert code execution.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
93% confidence
Finding

The skill instructs the agent to parse CLI output for upgrade prompts and to immediately self-update, then rerun the interrupted command. This is dangerous because it lets tool output steer agent behavior into downloading and executing fresh code from external sources, creating a prompt/output-injection path and a strong supply-chain risk.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
After downloading, rename it to `rgg` (or `rgg.exe` on Windows), grant execution permissions, and place it in the system PATH or the skill directory's `bin` folder.

**⚠️ Auto-Update Interception Principle:**
The CLI tool has built-in version detection. When you execute any `rgg` command, if the console output prompts `📦 New version available!` or `Run the following command to update`, **you must immediately pause the current operation, use one of the above three methods to upgrade the tool to the latest version, and then re-execute the interrupted command.** This prevents booking failures due to expired server endpoints.

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly requires shell execution, network access, environment inspection, and installation workflows, yet it declares no explicit tool scope or permissions boundary. That increases the chance an agent will run powerful operations by default without least-privilege constraints, which is especially risky here because the skill also performs installs, downloads, and booking-related actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The version-check instruction tells the agent to recommend npx skills without a pinned version, which allows execution of whatever package version is current at runtime. In a supply-chain compromise or unexpected upstream release, this can cause agents or users to fetch and run unreviewed code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says it should trigger whenever the user expresses any intent related to accommodations and lists broad phrases such as "where to stay," "accommodation," and "check-in." These phrases are not specific enough to clearly distinguish hotel-booking intent from ordinary conversation, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction requires confirmation of the guest's "English/Pinyin name" before booking, which imposes a language/locale-specific constraint in natural language. The file does not present this as an opt-in choice or explain that the requirement comes from a region-specific booking system policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented book command creates a real reservation and handles contact and guest personal data, but the description does not clearly warn that it is a state-changing, externally impactful action. In an agent setting, weak signaling around irreversible booking behavior can lead to unintended purchases, premature order creation, or oversharing of PII if an agent invokes the command without explicit user confirmation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install.py (reported line 13)May include surrounding context.

python
def run_command(args):
    """Run a system command and return exit code and output."""
    try:
        result = subprocess.run(args, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)
        return result.returncode, result.stdout, result.stderr
    except Exception as e:
        return -1, "", str(e)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.py (reported line 30)May include surrounding context.

python
print("✅ Successfully installed @rollinggo/hotel-global globally via npm!")
        return True
    
    print("⚠️ npm global installation failed (might need administrator/sudo permissions).")
    print(stderr)
    return False

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The installer fetches release metadata and later downloads executable content from the network, then installs it locally without any integrity verification such as a pinned checksum or signature. In an installer context this is more dangerous than ordinary API use, because a compromised release, redirected traffic endpoint, or supply-chain issue could result in execution of attacker-controlled code.

Content

Scanner excerpt · scripts/install.py (reported line 65)May include surrounding context.

python
def get_latest_release_assets():
    """Query GitHub API for the latest release assets."""
    api_url = "https://api.github.com/repos/RollingGo-AI/oauth-hotel-cli-overseas/releases/latest"
    req = urllib.request.Request(
        api_url,
        headers={'User-Agent': 'RollingGo-Installer/1.0'}

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install.py (reported line 87)May include surrounding context.

python
# Check if node and npm are available
    has_node = False
    try:
        node_code = subprocess.call(["node", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        npm_code = subprocess.call(["npm" if platform.system() != "Windows" else "npm.cmd", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        has_node = (node_code == 0 and npm_code == 0)
    except Exception:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install.py (reported line 88)May include surrounding context.

python
has_node = False
    try:
        node_code = subprocess.call(["node", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        npm_code = subprocess.call(["npm" if platform.system() != "Windows" else "npm.cmd", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        has_node = (node_code == 0 and npm_code == 0)
    except Exception:
        has_node = False

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently sets CLIENT_ID to rollinggoglobal whenever the variable is unset, forcing use of a default overseas client context without explicit user consent. This can redirect traffic, telemetry, or account association to an unintended service context and may violate user expectations or regional data-handling requirements in a booking workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code launches an external executable via child_process.spawn and, on Windows fallback, may do so with shell enabled while passing through user-supplied arguments. There is no confirmation prompt, visible disclosure, or explanatory comment warning users that the wrapper will execute external commands on their system.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/rgg.py (reported line 45)May include surrounding context.

python
args = [target_cmd] + sys.argv[1:]
    try:
        use_shell = is_win and target_cmd.endswith(".cmd")
        res = subprocess.run(args, shell=use_shell)
        sys.exit(res.returncode)
    except KeyboardInterrupt:
        sys.exit(130)

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
---

> ⚠️ **Output Specifications**:
> 1. **DO NOT show any technical details to users**, including but not limited to: tool names (like `search-hotels`, `hotel-detail`), JSON field names (like `hotelId`, `ratePlanId`, `referenceNo`), command line contents, or technical parameters.
> 2. **ONLY show information users care about**: Hotel name, star rating, price, distance, core facilities, tags, and booking link.
> 3. **Results MUST be formatted properly**, with each hotel occupying a separate card. Key information should be separated by line breaks, and stacking them in a single line is prohibited.
> 4. **Price Description**: Prices in search results are reference prices for display purposes. The actual order price is subject to price confirmation, and it must be labeled as "Reference Price" when displayed.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
---

> ⚠️ **Output Specifications**:
> 1. **DO NOT show any technical details to users**, including but not limited to: tool names (like `search-hotels`, `hotel-detail`), JSON field names (like `hotelId`, `ratePlanId`, `referenceNo`), command line contents, or technical parameters.
> 2. **ONLY show information users care about**: Hotel name, star rating, price, distance, core facilities, tags, and booking link.
> 3. **Results MUST be formatted properly**, with each hotel occupying a separate card. Key information should be separated by line breaks, and stacking them in a single line is prohibited.
> 4. **Price Description**: Prices in search results are reference prices for display purposes. The actual order price is subject to price confirmation, and it must be labeled as "Reference Price" when displayed.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/rgg.js:46