Back to skill

Security audit

Trip Website Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent static travel-site generator, but its templates can turn untrusted itinerary text into executable website code unless the user carefully controls or sanitizes inputs.

Install only if you will generate sites from trusted travel-plan content or will add escaping/validation before publishing. Treat itinerary fields, checklist IDs, class/style values, and SVG/icon content as untrusted input; otherwise a generated page could run injected JavaScript in the browser origin where it is opened or hosted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:32
Finding

Unescaped Template Substitution Permits Cross-Site Scripting in Generated Websites

Content
View full analysis
{{TRIP_TITLE}}
{{TRAVELERS}} | {{START_DATE}} - {{END_DATE}} | {{DURATION}}
{{DAY_NUMBER}}

{{DAY_TITLE}}

{{DATE}} | {{SUBTITLE}}

{{HOTEL}}
{{TIME}}
{{ACTIVITY}}
{{DETAIL}}
{{GUIDE_TITLE}} ▼
  • {{GUIDE_ITEM}}
  • {{TIP}}
    ``` An attribute-context sink appears in `templates/prepare.html:17-24`: ```html
    Remediation
    View remediation
    Vulnerability Patterns
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    Findings (16)

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

    md
    ## Template Variables
    
    Templates use `{{VARIABLE_NAME}}` syntax for placeholders. Repeatable sections are marked with HTML comments like `<!-- SECTION_START -->` and `<!-- SECTION_END -->`.
    
    ### Common Variables
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · templates/budget.html (reported line 26)May include surrounding context.

    html
    </div>
          </div>
    
          <!-- BUDGET_SECTION_START -->
          <div class="budget-section animate-in" style="animation-delay: {{ANIMATION_DELAY}}">
            <div class="budget-section-title">
              <span class="budget-section-icon">{{SECTION_ICON}}</span>
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

    md
    {{SECTION_TITLE}}
            </div>
            <div class="budget-card">
              <!-- BUDGET_ITEM_START -->
              <div class="budget-row">
                <div class="budget-item-name">
                  <span class="budget-item-dot"></span>
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · templates/budget.html (reported line 33)May include surrounding context.

    html
    {{SECTION_TITLE}}
            </div>
            <div class="budget-card">
              <!-- BUDGET_ITEM_START -->
              <div class="budget-row">
                <div class="budget-item-name">
                  <span class="budget-item-dot"></span>
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · templates/budget.html (reported line 41)May include surrounding context.

    html
    </div>
                <div class="budget-item-price">
                  {{ITEM_PRICE}}
                  <!-- ITEM_NOTE_START --><span class="budget-item-note">{{ITEM_NOTE}}</span><!-- ITEM_NOTE_END -->
                  <!-- ITEM_INCLUDED_START --><span class="budget-item-included">{{ITEM_INCLUDED}}</span><!-- ITEM_INCLUDED_END -->
                </div>
              </div>
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · templates/budget.html (reported line 42)May include surrounding context.

    html
    <div class="budget-item-price">
                  {{ITEM_PRICE}}
                  <!-- ITEM_NOTE_START --><span class="budget-item-note">{{ITEM_NOTE}}</span><!-- ITEM_NOTE_END -->
                  <!-- ITEM_INCLUDED_START --><span class="budget-item-included">{{ITEM_INCLUDED}}</span><!-- ITEM_INCLUDED_END -->
                </div>
              </div>
              <!-- BUDGET_ITEM_END -->
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

    md
    <!-- ITEM_INCLUDED_START --><span class="budget-item-included">{{ITEM_INCLUDED}}</span><!-- ITEM_INCLUDED_END -->
                </div>
              </div>
              <!-- BUDGET_ITEM_END -->
            </div>
          </div>
          <!-- BUDGET_SECTION_END -->
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · templates/budget.html (reported line 45)May include surrounding context.

    html
    <!-- ITEM_INCLUDED_START --><span class="budget-item-included">{{ITEM_INCLUDED}}</span><!-- ITEM_INCLUDED_END -->
                </div>
              </div>
              <!-- BUDGET_ITEM_END -->
            </div>
          </div>
          <!-- BUDGET_SECTION_END -->
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

    md
    <!-- BUDGET_ITEM_END -->
            </div>
          </div>
          <!-- BUDGET_SECTION_END -->
    
          <div class="budget-tip-card animate-in" style="animation-delay: 0.25s">
            <div class="budget-tip-icon">💡</div>
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · templates/budget.html (reported line 48)May include surrounding context.

    html
    <!-- BUDGET_ITEM_END -->
            </div>
          </div>
          <!-- BUDGET_SECTION_END -->
    
          <div class="budget-tip-card animate-in" style="animation-delay: 0.25s">
            <div class="budget-tip-icon">💡</div>
    

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The skill explicitly instructs the agent to always use Chinese unless the user specifies otherwise, which overrides user preference by default and can cause outputs in an unintended language. While not a classic security exploit, it is a policy/UX issue that may lead to incorrect or inaccessible responses and reduced user control.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The HTML document explicitly sets lang="zh-CN", and the visible interface text throughout the template is only in Simplified Chinese. This indicates a fixed language/locale choice without any visible opt-in, fallback, or explanation that the skill is intentionally region-specific.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The document declares lang="zh-CN", and the visible UI strings throughout the template are also fixed in Chinese. This imposes a specific language/locale on all users without any indication of opt-in, fallback, or region-specific justification, which matches the natural-language locale policy violation criteria.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The template sets the document language to zh-CN and all visible UI text is written in Simplified Chinese. This imposes a specific language/locale without any indication of user opt-in, alternative locale support, or a documented region-specific justification, which matches the natural-language policy violation criteria.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    This JavaScript file defines user-facing tab labels entirely in Chinese ('行程', '准备', '注意', '预算'). Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative or justification is provided.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The HTML root declares lang="zh-CN", and the visible UI text is entirely in Chinese, which indicates a fixed language/locale choice. The file does not present any user opt-in, language selection, or documented region-specific justification, so this is a natural-language locale policy concern.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.