Back to skill

Security audit

Lynx Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Lynx Reservations CLI, but it needs review because it handles live credentials and can mutate travel documents while also exposing real credential and debug-data handling risks.

Install only if you trust the publisher and the Lynx account scope. Avoid running it from untrusted directories, do not use plaintext .env files casually, do not run the documented env | grep LYNX check, and keep LYNX_DEBUG unset unless you have a private machine and can securely remove debug files afterward.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
client.go:218
Finding

Predictable world-readable debug files expose sensitive Lynx responses and permit symlink attacks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
gwt/build.go:5
Finding

Unescaped user-controlled values are interpolated into pipe-delimited GWT-RPC requests

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (72)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The README recommends loading secrets with export $(grep -v '^#' .env | xargs), an unsafe pattern that can expose credentials through shell parsing quirks, break on special characters, and encourage plaintext secret handling in a local file. In the context of a travel-system CLI using real Lynx credentials, mishandling these values can lead to credential disclosure and unauthorized access to itineraries, files, and uploaded documents.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

Puis chargez-le :

bash
export $(grep -v '^#' .env | xargs)

Ou utilisez direnv pour le chargement automatique.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The debug recipe env | grep LYNX will print authentication-related environment variables, including the password, directly to the terminal or logs. In an agent or recorded-session context, this can immediately expose live credentials to transcripts, shell history capture, CI logs, or other observers, enabling account compromise.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The documented .env auto-loader means the CLI automatically reads credentials from the working directory, creating an implicit secret-ingestion path. In shared or untrusted directories, an attacker could plant a .env file to influence which account is used, or cause accidental use of sensitive credentials without the operator realizing it.

Content

Scanner excerpt · SKILL.md (reported line 513)May include surrounding context.

md
├── lynx_architecture.md        # Full architecture document (decisions, comparisons)
│
├── cmd/                        # CLI commands — one file per command + dispatcher
│   ├── cmd.go                  # Command registry, dispatcher, .env auto-loader, config
│   ├── file_search_by_party_name.go
│   ├── file_search_by_file_reference.go
│   ├── retrieve_itinerary.go

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This section explicitly documents that the program reads .env from the current working directory at startup. Because the skill authenticates to a real reservations system and supports data-modifying actions, implicit credential loading materially increases the risk of secret misuse, credential confusion, and attacker-controlled environment injection when run from untrusted project folders.

Content

Scanner excerpt · SKILL.md (reported line 544)May include surrounding context.

md
The `ParseFileSearchResponse` function uses **backward scanning**: it iterates from the last element backward, identifies `FileSearchResults` type markers, and extracts 10 fields per result. This approach correctly handles multi-result responses (tested with 10 results in `parse_test.go`).

### 2. .env Auto-Load (Convenience vs Security)

`cmd/cmd.go:13-33` implements a lightweight `.env` loader — no external dependency. It reads `.env` from the working directory at startup:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cmd/cmd.go (reported line 14)May include surrounding context.

go
}

func loadDotenv() {
	data, err := os.ReadFile(".env")
	if err != nil {
		return
	}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dotenv.go (reported line 13)May include surrounding context.

go
}

func loadDotenv() {
	data, err := os.ReadFile(".env")
	if err != nil {
		return
	}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 507)May include surrounding context.

md
├── go.mod                      # Module: dodmcdund.cc/lynx-travel-agent/lynxskill (Go 1.23.10)
├── go.sum
├── .gitignore                  # Ignores /bin/, /lynxskill
├── .env                        # Local credentials (gitignored?)
├── SKILL.md                    # OpenClaw skill definition (YAML frontmatter + docs)
├── README.md                   # User-facing documentation
├── lynx_architecture.md        # This file

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lynx_architecture.md (reported line 123)May include surrounding context.

md
├── go.mod                      # Module: dodmcdund.cc/lynx-travel-agent/lynxskill (Go 1.23.10)
├── go.sum
├── .gitignore                  # Ignores /bin/, /lynxskill
├── .env                        # Local credentials (gitignored?)
├── SKILL.md                    # OpenClaw skill definition (YAML frontmatter + docs)
├── README.md                   # User-facing documentation
├── lynx_architecture.md        # This file

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lynx_architecture.md (reported line 312)May include surrounding context.

md
├── go.mod                      # Module: dodmcdund.cc/lynx-travel-agent/lynxskill (Go 1.23.10)
├── go.sum
├── .gitignore                  # Ignores /bin/, /lynxskill
├── .env                        # Local credentials (gitignored?)
├── SKILL.md                    # OpenClaw skill definition (YAML frontmatter + docs)
├── README.md                   # User-facing documentation
├── lynx_architecture.md        # This file

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lynx_architecture.md (reported line 431)May include surrounding context.

md
├── go.mod                      # Module: dodmcdund.cc/lynx-travel-agent/lynxskill (Go 1.23.10)
├── go.sum
├── .gitignore                  # Ignores /bin/, /lynxskill
├── .env                        # Local credentials (gitignored?)
├── SKILL.md                    # OpenClaw skill definition (YAML frontmatter + docs)
├── README.md                   # User-facing documentation
├── lynx_architecture.md        # This file

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lynx_architecture.md (reported line 478)May include surrounding context.

md
├── go.mod                      # Module: dodmcdund.cc/lynx-travel-agent/lynxskill (Go 1.23.10)
├── go.sum
├── .gitignore                  # Ignores /bin/, /lynxskill
├── .env                        # Local credentials (gitignored?)
├── SKILL.md                    # OpenClaw skill definition (YAML frontmatter + docs)
├── README.md                   # User-facing documentation
├── lynx_architecture.md        # This file

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lynx_architecture.md (reported line 516)May include surrounding context.

md
├── go.mod                      # Module: dodmcdund.cc/lynx-travel-agent/lynxskill (Go 1.23.10)
├── go.sum
├── .gitignore                  # Ignores /bin/, /lynxskill
├── .env                        # Local credentials (gitignored?)
├── SKILL.md                    # OpenClaw skill definition (YAML frontmatter + docs)
├── README.md                   # User-facing documentation
├── lynx_architecture.md        # This file

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 43)May include surrounding context.

md
### 2.1 `file_search_by_party_name`

| Champ                | Valeur                                                                                                                                   |
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**          | `file_search_by_party_name`                                                                                                              |
| **Description**      | Retrieve file from party name                                                                                                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 45)May include surrounding context.

md
| Champ                | Valeur                                                                                                                                   |
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**          | `file_search_by_party_name`                                                                                                              |
| **Description**      | Retrieve file from party name                                                                                                            |
| **Paramètres**       | `partyName` (string, **required**)                                                                                                       |
| **Endpoint**         | `POST /lynx/service/file.rpc`                                                                                                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 46)May include surrounding context.

md
| Champ                | Valeur                                                                                                                                   |
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**          | `file_search_by_party_name`                                                                                                              |
| **Description**      | Retrieve file from party name                                                                                                            |
| **Paramètres**       | `partyName` (string, **required**)                                                                                                       |
| **Endpoint**         | `POST /lynx/service/file.rpc`                                                                                                            |
| **Méthode GWT**      | `FileService.search(FileSearchCriteria)`                                                                                                 |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 48)May include surrounding context.

md
| Champ                | Valeur                                                                                                                                   |
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**          | `file_search_by_party_name`                                                                                                              |
| **Description**      | Retrieve file from party name                                                                                                            |
| **Paramètres**       | `partyName` (string, **required**)                                                                                                       |
| **Endpoint**         | `POST /lynx/service/file.rpc`                                                                                                            |
| **Méthode GWT**      | `FileService.search(FileSearchCriteria)`                                                                                                 |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 47)May include surrounding context.

md
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**          | `file_search_by_party_name`                                                                                                              |
| **Description**      | Retrieve file from party name                                                                                                            |
| **Paramètres**       | `partyName` (string, **required**)                                                                                                       |
| **Endpoint**         | `POST /lynx/service/file.rpc`                                                                                                            |
| **Méthode GWT**      | `FileService.search(FileSearchCriteria)`                                                                                                 |
| **Réponse**          | `{ count: int, results: Array<FileSearchResult> }`                                                                                       |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 49)May include surrounding context.

md
| **Description**      | Retrieve file from party name                                                                                                            |
| **Paramètres**       | `partyName` (string, **required**)                                                                                                       |
| **Endpoint**         | `POST /lynx/service/file.rpc`                                                                                                            |
| **Méthode GWT**      | `FileService.search(FileSearchCriteria)`                                                                                                 |
| **Réponse**          | `{ count: int, results: Array<FileSearchResult> }`                                                                                       |
| **FileSearchResult** | `companyCode`, `clientIdentifier`, `clientReference`, `currency`, `fileIdentifier`, `fileReference`, `partyName`, `status`, `travelDate` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 50)May include surrounding context.

md
| **Paramètres**       | `partyName` (string, **required**)                                                                                                       |
| **Endpoint**         | `POST /lynx/service/file.rpc`                                                                                                            |
| **Méthode GWT**      | `FileService.search(FileSearchCriteria)`                                                                                                 |
| **Réponse**          | `{ count: int, results: Array<FileSearchResult> }`                                                                                       |
| **FileSearchResult** | `companyCode`, `clientIdentifier`, `clientReference`, `currency`, `fileIdentifier`, `fileReference`, `partyName`, `status`, `travelDate` |

### 2.2 `file_search_by_file_reference`

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 66)May include surrounding context.

md
### 2.3 `retrieve_itinerary`

| Champ                           | Valeur                                                                                                                                                  |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**                     | `retrieve_itinerary`                                                                                                                                    |
| **Description**                 | Retrieve file itinerary                                                                                                                                 |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 68)May include surrounding context.

md
| Champ                           | Valeur                                                                                                                                                  |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**                     | `retrieve_itinerary`                                                                                                                                    |
| **Description**                 | Retrieve file itinerary                                                                                                                                 |
| **Paramètres**                  | `fileIdentifier` (string, **required**)                                                                                                                 |
| **Endpoint**                    | `POST /lynx/service/file.rpc`                                                                                                                           |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 69)May include surrounding context.

md
| Champ                           | Valeur                                                                                                                                                  |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**                     | `retrieve_itinerary`                                                                                                                                    |
| **Description**                 | Retrieve file itinerary                                                                                                                                 |
| **Paramètres**                  | `fileIdentifier` (string, **required**)                                                                                                                 |
| **Endpoint**                    | `POST /lynx/service/file.rpc`                                                                                                                           |
| **Méthode GWT**                 | `FileService.retrieveItinerary(Long)`                                                                                                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 70)May include surrounding context.

md
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Nom MCP**                     | `retrieve_itinerary`                                                                                                                                    |
| **Description**                 | Retrieve file itinerary                                                                                                                                 |
| **Paramètres**                  | `fileIdentifier` (string, **required**)                                                                                                                 |
| **Endpoint**                    | `POST /lynx/service/file.rpc`                                                                                                                           |
| **Méthode GWT**                 | `FileService.retrieveItinerary(Long)`                                                                                                                   |
| **Réponse**                     | `{ type, partyName, fileReference, fileIdentifier, clientIdentifier, agentReference, itineraryCount, itineraries: Array<ItineraryTransactionSummary> }` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 71)May include surrounding context.

md
| **Nom MCP**                     | `retrieve_itinerary`                                                                                                                                    |
| **Description**                 | Retrieve file itinerary                                                                                                                                 |
| **Paramètres**                  | `fileIdentifier` (string, **required**)                                                                                                                 |
| **Endpoint**                    | `POST /lynx/service/file.rpc`                                                                                                                           |
| **Méthode GWT**                 | `FileService.retrieveItinerary(Long)`                                                                                                                   |
| **Réponse**                     | `{ type, partyName, fileReference, fileIdentifier, clientIdentifier, agentReference, itineraryCount, itineraries: Array<ItineraryTransactionSummary> }` |
| **ItineraryTransactionSummary** | `voucherIdentifier`, `date`, `transactionIdentifier`, `supplier`, `status`, `confirmationNumber`, `location`                                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · INSPECT.md (reported line 72)May include surrounding context.

md
| **Description**                 | Retrieve file itinerary                                                                                                                                 |
| **Paramètres**                  | `fileIdentifier` (string, **required**)                                                                                                                 |
| **Endpoint**                    | `POST /lynx/service/file.rpc`                                                                                                                           |
| **Méthode GWT**                 | `FileService.retrieveItinerary(Long)`                                                                                                                   |
| **Réponse**                     | `{ type, partyName, fileReference, fileIdentifier, clientIdentifier, agentReference, itineraryCount, itineraries: Array<ItineraryTransactionSummary> }` |
| **ItineraryTransactionSummary** | `voucherIdentifier`, `date`, `transactionIdentifier`, `supplier`, `status`, `confirmationNumber`, `location`                                            |

Static analysis

No suspicious patterns detected.