Back to skill

Security audit

Crypto Traveler - Book Hotels and Flights with Bitcoin

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent CryptoTraveler API guide for travel search and booking, with ordinary credential and personal-data risks that users should handle carefully.

Install only if you are comfortable letting the agent use CryptoTraveler API credentials and, when authorized, access booking/account data. Store real CLIENT_SECRET and USER_ACCESS values outside prompts, logs, repositories, and shared project folders, and prefer a secret manager or tightly permissioned local storage.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:1043
Finding

Plaintext Storage of API Credentials and User Access Tokens

Content
View full analysis
dict: if not CREDENTIALS_PATH.exists(): raise SystemExit(f"Credential file not found: {CREDENTIALS_PATH}") data = json.loads(CREDENTIALS_PATH.read_text(encoding="utf-8")) required = {"client_id", "client_secret"} missing = required - data.keys() if missing: raise SystemExit(f"Credentials file missing keys: {', '.join(sorted(missing))}") return data ``` ### Technical Analysis The documented implementation directs users to store `client_id`, `client_secret`, and the optional `user_access` token in a predictable plaintext file in the current working directory. The example credential values are placeholders rather than exposed live secrets, but users following the documented workflow would replace them with real credentials. No controls are specified for restrictive file permissions, storage outside the project directory, exclusion from version control, encryption at rest, or integration with an operating-system keychain or secret manager. Consequently, credentials may be exposed to other local users or processes, source-control history, automated backups, artifact packaging, or accidental file sharing. The `client_secret` is used to derive authentication signatures. The `user_access` token is sent as a raw request header and permits access to user-specific account and booking endpoints within the permissions granted to it. Therefore, disclosure of the credential file could enable authenticated API requests without the legitim ...[truncated 1928 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 174)May include surrounding context.

When X-USER-ACCESS is used, the canonical signing string must include:

text
USER_ACCESS_HASH = sha256(raw X-USER-ACCESS token)

If X-USER-ACCESS is not used, USER_ACCESS_HASH is an empty string.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 1044)May include surrounding context.

Example credentials file:

cryptotraveler_credentials.json

json
{

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 1072)May include surrounding context.

Example credentials file:

cryptotraveler_credentials.json

json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explains that USER_ACCESS enables access to user-specific booking and account data, and later sections collect passenger, guest, and contact details, but the markdown does not clearly warn users that using these flows will transmit sensitive personal data to CryptoTraveler systems. For a markdown skill description, this is a missing disclosure about behavior that could affect user privacy and user data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example credentials block includes realistic-looking secret material and a user access token format, which can normalize copying secrets into prompts, markdown, logs, or troubleshooting messages. Even if the values are placeholders, presenting them inline in a shareable skill file increases the chance that operators mishandle real credentials by imitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.