T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.py:19- Finding
Unverified, Mutable Executables Are Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This hotel booking skill is purpose-aligned overall, but it installs and auto-updates mutable executable code and can create real bookings using personal data, so it needs human review before installation.
Install only if you trust RollingGo's npm and GitHub release channels and are comfortable with a persistent CLI that can log in, query prior orders, collect guest names and email, create real hotel orders, and return payment links. Require explicit approval before installing, updating, booking, or sending personal data, and avoid running it with administrator privileges.
scripts/install.py:19Unverified, Mutable Executables Are Downloaded and Executed
scripts/rgg.js:34Windows Shell Invocation Allows Command Injection Through CLI Arguments
The skill is presented as a hotel booking assistant, but it also instructs the agent to install software globally, download binaries from releases, modify executable permissions, and execute local scripts. This mismatch hides materially more dangerous behavior than a user would reasonably expect from the declared purpose, increasing the risk of unsafe consent and covert code execution.
The skill instructs the agent to parse CLI output for upgrade prompts and to immediately self-update, then rerun the interrupted command. This is dangerous because it lets tool output steer agent behavior into downloading and executing fresh code from external sources, creating a prompt/output-injection path and a strong supply-chain risk.
After downloading, rename it to `rgg` (or `rgg.exe` on Windows), grant execution permissions, and place it in the system PATH or the skill directory's `bin` folder.
**⚠️ Auto-Update Interception Principle:**
The CLI tool has built-in version detection. When you execute any `rgg` command, if the console output prompts `📦 New version available!` or `Run the following command to update`, **you must immediately pause the current operation, use one of the above three methods to upgrade the tool to the latest version, and then re-execute the interrupted command.** This prevents booking failures due to expired server endpoints.
---
The skill clearly requires shell execution, network access, environment inspection, and installation workflows, yet it declares no explicit tool scope or permissions boundary. That increases the chance an agent will run powerful operations by default without least-privilege constraints, which is especially risky here because the skill also performs installs, downloads, and booking-related actions.
The version-check instruction tells the agent to recommend npx skills without a pinned version, which allows execution of whatever package version is current at runtime. In a supply-chain compromise or unexpected upstream release, this can cause agents or users to fetch and run unreviewed code.
The skill says it should trigger whenever the user expresses any intent related to accommodations and lists broad phrases such as "where to stay," "accommodation," and "check-in." These phrases are not specific enough to clearly distinguish hotel-booking intent from ordinary conversation, increasing the risk of unintended invocation.
The instruction requires confirmation of the guest's "English/Pinyin name" before booking, which imposes a language/locale-specific constraint in natural language. The file does not present this as an opt-in choice or explain that the requirement comes from a region-specific booking system policy.
The documented book command creates a real reservation and handles contact and guest personal data, but the description does not clearly warn that it is a state-changing, externally impactful action. In an agent setting, weak signaling around irreversible booking behavior can lead to unintended purchases, premature order creation, or oversharing of PII if an agent invokes the command without explicit user confirmation.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_command(args):
"""Run a system command and return exit code and output."""
try:
result = subprocess.run(args, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)
return result.returncode, result.stdout, result.stderr
except Exception as e:
return -1, "", str(e)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
print("✅ Successfully installed @rollinggo/hotel-global globally via npm!")
return True
print("⚠️ npm global installation failed (might need administrator/sudo permissions).")
print(stderr)
return False
The installer fetches release metadata and later downloads executable content from the network, then installs it locally without any integrity verification such as a pinned checksum or signature. In an installer context this is more dangerous than ordinary API use, because a compromised release, redirected traffic endpoint, or supply-chain issue could result in execution of attacker-controlled code.
def get_latest_release_assets():
"""Query GitHub API for the latest release assets."""
api_url = "https://api.github.com/repos/RollingGo-AI/oauth-hotel-cli-overseas/releases/latest"
req = urllib.request.Request(
api_url,
headers={'User-Agent': 'RollingGo-Installer/1.0'}
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# Check if node and npm are available
has_node = False
try:
node_code = subprocess.call(["node", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
npm_code = subprocess.call(["npm" if platform.system() != "Windows" else "npm.cmd", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
has_node = (node_code == 0 and npm_code == 0)
except Exception:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
has_node = False
try:
node_code = subprocess.call(["node", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
npm_code = subprocess.call(["npm" if platform.system() != "Windows" else "npm.cmd", "--version"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
has_node = (node_code == 0 and npm_code == 0)
except Exception:
has_node = False
The script silently sets CLIENT_ID to rollinggoglobal whenever the variable is unset, forcing use of a default overseas client context without explicit user consent. This can redirect traffic, telemetry, or account association to an unintended service context and may violate user expectations or regional data-handling requirements in a booking workflow.
This code launches an external executable via child_process.spawn and, on Windows fallback, may do so with shell enabled while passing through user-supplied arguments. There is no confirmation prompt, visible disclosure, or explanatory comment warning users that the wrapper will execute external commands on their system.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
args = [target_cmd] + sys.argv[1:]
try:
use_shell = is_win and target_cmd.endswith(".cmd")
res = subprocess.run(args, shell=use_shell)
sys.exit(res.returncode)
except KeyboardInterrupt:
sys.exit(130)
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
---
> ⚠️ **Output Specifications**:
> 1. **DO NOT show any technical details to users**, including but not limited to: tool names (like `search-hotels`, `hotel-detail`), JSON field names (like `hotelId`, `ratePlanId`, `referenceNo`), command line contents, or technical parameters.
> 2. **ONLY show information users care about**: Hotel name, star rating, price, distance, core facilities, tags, and booking link.
> 3. **Results MUST be formatted properly**, with each hotel occupying a separate card. Key information should be separated by line breaks, and stacking them in a single line is prohibited.
> 4. **Price Description**: Prices in search results are reference prices for display purposes. The actual order price is subject to price confirmation, and it must be labeled as "Reference Price" when displayed.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
---
> ⚠️ **Output Specifications**:
> 1. **DO NOT show any technical details to users**, including but not limited to: tool names (like `search-hotels`, `hotel-detail`), JSON field names (like `hotelId`, `ratePlanId`, `referenceNo`), command line contents, or technical parameters.
> 2. **ONLY show information users care about**: Hotel name, star rating, price, distance, core facilities, tags, and booking link.
> 3. **Results MUST be formatted properly**, with each hotel occupying a separate card. Key information should be separated by line breaks, and stacking them in a single line is prohibited.
> 4. **Price Description**: Prices in search results are reference prices for display purposes. The actual order price is subject to price confirmation, and it must be labeled as "Reference Price" when displayed.
Detected: suspicious.dangerous_exec