Back to skill

Security audit

travel-agent

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible travel assistant, but reviewed code fabricates travel data and has weak handling of secrets, logs, and recurring external pushes.

Review before installing. Do not use production API keys or real messaging webhooks until the publisher fixes fabricated data generation, webhook secret handling, context logging, recurring push controls, and the broken entry-point wiring. Assume pushed reports are sent to third-party messaging or email systems.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
main.py:458
Finding

Sensitive Context Values May Be Exposed in Application Logs

Content
View full analysis
= 16 else m.group(0), content) # 掩码敏感关键词对应的值 for keyword in SENSITIVE_KEYWORDS: # 匹配 key: value 格式 pattern = re.compile(rf"({keyword}[\"']?\s*[=:]\s*[\"']?)([A-Za-z0-9_\-./+]+)([\"']?)", re.IGNORECASE) content = pattern.sub(lambda m: f"{m.group(1)}{m.group(2)[:4]}****{m.group(2)[-4:]}{m.group(3)}", content) ``` ### Technical Analysis The program logs the complete command arguments and context after applying `filter_sensitive_data()` independently to each context value. Because the key and value are separated before filtering, key-aware patterns such as `api_key=value`, `password=value`, or `token=value` cannot identify a sensitive value based on its original context key. The remaining standalone patterns only cover limited token formats. They do not reliably redact webhook URLs, session identifiers, cookies, short tokens, bearer credentials, email addresses, or API keys that do not match the expected length and character set. Sanitized command arguments are also logged in full and may contain private travel plans or other personal data. ### Attack Path 1. A user or platform places a sensitive value in a context field, such as a webhook URL, session token, or nonstandard API key. 2. The user invokes any Skill command. 3. `main()` converts the value ...[truncated 793 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill.json:82
Finding

Messaging Webhook Credentials Are Declared as Non-Secret Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
main.py:517
Finding

Raw Internal Exception Details Are Returned to Skill Users

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
skill.json:13
Finding

Unused Agent Dependency Exceeds the Skill's Minimum Functional Requirements

Content
View full analysis
=0.8.0", "skills": [ "baidu-search", "multi-search-engine", "self-improving-agent", "message" ] } ``` ### Technical Analysis The manifest requires `self-improving-agent`, but no source call to that Skill was found. The declared travel functionality uses search and messaging integrations; an agent-oriented dependency is not necessary for the observed implementation. Although the audit found no evidence that this dependency is malicious, installing or enabling unused components increases the supply-chain and privilege surface. A future compromise, behavioral change, or excessive permission in that component would affect installations even though the dependency contributes no required functionality. ### Attack Path 1. The Skill is installed and its declared requirements are resolved. 2. The unused `self-improving-agent` component is installed or made available to the runtime. 3. The dependency is later compromised, replaced, or updated with unsafe behavior. 4. The unnecessary component executes through platform lifecycle behavior or becomes available to other orchestration logic. 5. The installation is exposed to capabilities that were not required for travel monitoring or report delivery. This path is conditional on dependency or platform behavior; no active exploitation of the dependency was identified in the audited source. ### Impact Assessment The exact privileges depend on the external dependency and OpenClaw runtime. The confirmed impact is an unnecessary increase in attack surface rather than an observed compromise. Potential scope includes any permissions granted to or inherited by the dependency. ]]>
Remediation
View remediation

other

Error
Location
main.py:474
Finding

Entry-Point API and Constructor Mismatches Prevent Security Controls and Commands from Operating Reliably

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (43)

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · core/security.py (reported line 158)May include surrounding context.

python
"you are now",
        "act as",
        "new instructions",
        "override system",
        "bypass security",
    ]

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · core/security.py (reported line 159)May include surrounding context.

python
"act as",
        "new instructions",
        "override system",
        "bypass security",
    ]
    
    for keyword in injection_keywords:

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This function claims to search attractions for an arbitrary city but always returns hard-coded Beijing locations, regardless of input or search results. That creates deceptive output and can systematically mislead users, especially when used in itinerary generation, recommendations, or automated reports presented as city-specific intelligence.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The transportation search routine claims to retrieve city-specific transport information but returns fixed Beijing-specific stations and airport naming patterns while ignoring fetched data. This is dangerous because it can produce confidently wrong logistics guidance for other cities, undermining safety and trust in travel recommendations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

The entire skill-facing changelog is written only in Chinese, and there is no indication that users can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog explicitly states that user behavior and preference data will be collected for product iteration, but provides no indication of user notice, consent, minimization, retention limits, or opt-out controls. In a user-facing skill, undisclosed telemetry and profiling can create privacy, compliance, and trust risks, especially if the collected data is tied to identifiable usage patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

该 markdown 文件的全部标题与说明均以中文呈现,但未声明这是面向特定中文用户群体的区域化文档,也未提供其他语言选项或用户选择机制。根据语言/locale 政策,未经说明地强制单一语言可能构成自然语言层面的组织政策违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README advertises scheduled push delivery via Feishu/DingTalk webhooks but does not warn that generated reports may be transmitted to third-party messaging platforms outside the core skill boundary. This can lead users to unknowingly send travel reports, preferences, or other potentially sensitive content to external services, increasing privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration section asks users to provide multiple sensitive credentials, including model API keys, Baidu keys, and webhook endpoints, but gives no security handling guidance. In a skill ecosystem, users may paste secrets into unsafe places, share screenshots/logs, or misunderstand how credentials are stored and used, which raises the likelihood of credential leakage or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is natural-language documentation, and all user-facing content is presented only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises scheduled delivery of travel monitoring reports to Feishu, DingTalk, and other external channels without clearly warning users that report contents may leave the platform and be stored or exposed in third-party systems. This creates a real privacy and data-handling risk, especially if reports contain business intelligence, personal itineraries, or location-related data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill requires users to supply multiple sensitive credentials, including model API keys, Baidu API keys, and messaging webhooks, but does not provide adequate warnings about their sensitivity, scope, or safe handling responsibilities. If users paste overprivileged or reused secrets without understanding the risk, credential theft, account abuse, billing fraud, or unauthorized message delivery could result.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · core/config.py (reported line 21)May include surrounding context.

python
# 从 OpenClaw 配置系统获取配置
        # 本地开发时从环境变量读取
        self.llm_api_key = self._get_config("LLM_API_KEY", os.getenv("llm_api_key", ""))
        self.llm_base_url = self._get_config("LLM_BASE_URL", os.getenv("llm_base_url", "https://api.openai.com/v1"))
        self.llm_model = self._get_config("LLM_MODEL", os.getenv("llm_model", "gpt-3.5-turbo"))
        
        self.baidu_search_api_key = self._get_config("BAIDU_SEARCH_API_KEY", os.getenv("baidu_search_api_key", ""))

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 55)May include surrounding context.

json
# 从 OpenClaw 配置系统获取配置
        # 本地开发时从环境变量读取
        self.llm_api_key = self._get_config("LLM_API_KEY", os.getenv("llm_api_key", ""))
        self.llm_base_url = self._get_config("LLM_BASE_URL", os.getenv("llm_base_url", "https://api.openai.com/v1"))
        self.llm_model = self._get_config("LLM_MODEL", os.getenv("llm_model", "gpt-3.5-turbo"))
        
        self.baidu_search_api_key = self._get_config("BAIDU_SEARCH_API_KEY", os.getenv("baidu_search_api_key", ""))

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sets the skill's default language/locale to "zh-CN" in a configuration value, and the file does not show any mechanism for user selection or explicit opt-in. That can violate language/locale policy when a skill forces a specific locale by default rather than offering a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module description and all generated report content are hard-coded in Chinese, indicating the skill is designed to produce output in a single language. Although self.language is set from configuration, it is never used to offer or honor a user language choice, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module docstring is entirely in Chinese, and the rest of the user-facing comments/docstrings throughout the file also assume Chinese as the required language. Under the policy, forcing a specific language without opt-in or a documented justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The method presents itself as fetching real weather data via an external search skill, but it ignores the returned result and fabricates random forecasts. This is dangerous because downstream users or automations may trust the output for travel planning, causing materially incorrect decisions while the code gives the false impression of live-data grounding.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The helper sends user-derived queries plus API credentials to an external skill, and this execution path shows no assurance of minimization, disclosure, or boundary enforcement. Passing secrets through generic cross-skill invocations increases the attack surface because a compromised or over-privileged downstream skill could capture credentials or sensitive request context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code invokes multi-platform search but discards the actual results and generates random sentiment metrics and complaint points. This can misrepresent public sentiment and complaints in a way that appears evidence-based, which is especially risky if outputs inform reports, alerts, or business decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The weather query path performs an external call but returns entirely random weather values unrelated to the response. This is a deceptive implementation that can mislead users into acting on fabricated environmental conditions while believing the result is a live weather lookup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code pushes generated reports to Feishu, DingTalk, and email channels without any visible confirmation, review, or content-safety gate in this execution path. If the report contains sensitive user information, inaccurate generated content, or attacker-influenced text, the system may automatically exfiltrate or spread it to external recipients.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This module returns user-facing messages in both Chinese and English, such as the English-only subscription expiry notice here, while other messages are Chinese or mixed-language. That creates a language-policy risk because the skill effectively imposes output language inconsistently without user opt-in or a documented locale-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings throughout the file require Chinese commands such as 对比分析, 定时推送, 自定义报告, and 文旅帮助, and user-facing messages are also in Chinese. This enforces a specific language/locale without visible user opt-in or an explicit documented regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code enables a recurring push task for a user via setup_scheduled_push, which is a persistent operation affecting future notifications and likely continued use of user preference or reporting data. While the success message explains what will happen after creation, there is no confirmation step or pre-execution warning before the recurring task is established.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.