Back to skill

Security audit

智能旅游规划师

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese travel-planning skill that uses expected web lookup and image-generation assistance, with no evidence of hidden persistence, credential access, exfiltration, or destructive behavior.

Before installing, be aware that the skill is designed primarily for Chinese-language travel planning and expects to query current travel information and use an image-generation service for itinerary cards. Avoid sharing unnecessary sensitive personal details, and ask the agent to use your preferred language or skip external image generation if that matters to you.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a travel-planning assistant, but the supplied code is a local build/deployment tool for packaging a skill directory into a .skill file. It performs filesystem access, reads metadata, and writes an archive; it does not implement any travel-planning, personalization, recommendation, interactive consultation, or dynamic itinerary adjustment behavior. This is a clear primary-purpose mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

L114-L116 要求每个小节使用“中文短语”,并进一步规定“文字内容均采用中文草书”,这对输出语言作了强制限定且未提供用户选择。该技能服务对象包含国际旅游场景和不同用户群体,缺少用户语言偏好或本地化选项,构成自然语言层面的语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L003 在描述中规定使用亲切生动的语言风格并称呼用户为“亲”,这是对称谓和语言风格的强制设定。该要求没有提供用户选择或退出机制,对部分用户或语言环境可能不适配,属于自然语言策略上的固定 locale/风格约束。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L018 将触发条件描述为“用户表达旅游规划需求”,并仅给出几个开放式示例,没有限定触发边界、上下文范围或不触发的反例。像“家庭亲子游建议”这类短语与普通聊天中的泛化旅游咨询高度重叠,容易造成技能在不期望场景下被调用。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to perform external web searches for weather, transport, policy changes, and safety alerts before planning, but it does not require notifying the user or obtaining consent. This can expose user travel intent, destination, and timing to third-party services unexpectedly, creating privacy and transparency risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

L138 在注意事项中再次要求“称呼用户为‘亲’”,将这一语言风格约束固化为通用规则。由于没有提供用户偏好选择、适用场景说明或可替代称谓,这会造成对称谓和语气的单一强制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing instructions and examples exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into another language. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s only human-facing description is the Chinese docstring "打包技能为 .skill 文件", which imposes a specific language choice in natural-language content. There is no indication that the tool is region-specific or that users can choose their preferred language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.