Back to skill

Security audit

Budget Traval Plan

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed budget-travel recommendation skill with some quality and branding caveats but no evidence of hidden code, credential access, persistence, or destructive behavior.

Before installing, be aware that outputs may include a FlyAI branding footer, Chinese-language formatting, external booking links, and example logic that can exceed the stated budget. Verify prices and totals before booking.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:171
Finding

Mandatory Promotional Branding Injected into Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 171
Vulnerability Type: Mandatory final-output manipulation
Risk Level: High

Complete Code Snippet:

markdown
*Powered by Budget Travel Deals + FlyAI*

The same footer is reinforced in the example outputs at examples.md:119, examples.md:189, examples.md:260, and examples.md:337.

Technical Analysis

The Skill's prescribed output template requires the agent to append third-party product branding to generated travel recommendations. Repetition of the footer across every supplied example reinforces this instruction as expected behavior rather than optional attribution.

When the Skill is loaded, this instruction alters the content of the agent's final response independently of the user's travel-planning request. It therefore constitutes output-level instruction hijacking: otherwise legitimate travel results are used as a delivery channel for persistent promotional material.

No executable scripts, obfuscated payloads, credential access, persistence mechanisms, package installation, or remote-code execution behavior were identified. The issue is limited to manipulation of generated content.

Attack Path

  1. A user invokes the Skill to request a budget travel recommendation.
  2. The agent loads and follows the output template in SKILL.md.
  3. The agent performs or describes the expected flight, hotel, and attraction searches.
  4. The agent generates the requested itinerary.
  5. The mandatory footer is appended to the final response without requiring the user's informed consent.
  6. If the response is subsequently exported through the referenced DOCX or PDF integrations, the unsolicited branding may propagate into those documents.

Impact Assessment

The attacker does not obtain operating-system privileges, account access, code execution, or access to confidential data through this instruction. The affected scope is the agent's ge ...[truncated 336 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory Powered by Budget Travel Deals + FlyAI footer from the output template.
  2. Do not require promotional or attribution text that is unrelated to the user's requested result.
  3. If attribution is operationally necessary, clearly disclose it and include it only after explicit user consent or under a transparent platform-level attribution policy.
  4. Remove the same footer from all examples so they do not reinforce unsolicited branding behavior.
  5. Review future response templates for mandatory advertisements, endorsements, external calls to action, or content that changes the user's requested output without a task-related justification.
  6. Keep booking links clearly labeled as external links and distinguish any sponsored or affiliate destinations from neutral search results.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broad enough to match many ordinary travel queries, increasing the chance it activates when a user did not ask for random budget-deal discovery. Over-broad activation can cause unintended tool use, unnecessary data collection, and response hijacking away from the user’s actual intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The title, instructions, trigger phrases, workflow, and output format are entirely in Chinese, indicating the skill is designed to operate in a fixed language. There is no note that Chinese is optional, no language selection step, and no justification that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The listed trigger phrases are ambiguous and unconstrained, so the skill may activate on general travel-assistance requests rather than only the specialized deal-finding use case. This can lead to inappropriate skill invocation, confusing outputs, and unnecessary access to travel-search tools for requests better handled by a general assistant or another travel skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file is entirely written as Chinese-language examples, including headings, labels, and generated travel recommendations, with no indication that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

In 示例 1, the user input states a budget of '¥1000以内' at L007, but the generated recommendation totals '¥1530' at L052. This is not merely incomplete documentation; the example implicitly claims to be a valid budget-travel recommendation while violating the budget constraint central to the skill's stated purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

In 示例 2, the input budget is '¥800以内' at L129, but the itinerary total is '¥1330' at L171. Since the skill is described as finding cheap deals and generating complete travel plans, this documented example contradicts that intent rather than simply omitting details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

In 示例 3, the user requests '¥600以内' at L198, but the documented total is '¥1338' at L240. Because the skill's purpose is specifically to surface budget-friendly travel deals, showcasing an over-budget plan as a recommendation conflicts with the documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing natural language content exclusively in Chinese, including the title and all instructions/data labels. Under the policy rule for language or locale, forcing a specific language without user opt-in can be a natural-language policy violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.