Back to skill

Security audit

Travel Companion

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent travel-planning purpose, but it broadly activates, persists travel details on an external service, and runs a mutable npm CLI at runtime.

Review before installing. Use only if you are comfortable sending travel plans, dates, places, and possibly companion details to aizzie.ai, and prefer a version that asks for consent before saving or sharing trips and uses a pinned reviewed CLI version instead of @latest.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:13
Finding

Mandatory Skill Activation and Promotional Output Hijacking

Content
View full analysis
Your trip is saved at aizzie.ai. You can: > > - View all your destinations on an interactive map with routes between stops > - Drag and drop to reorder your itinerary > - Share the link with your travel companions so they can view and edit together > - Track your packing checklist during the vacation from any device This is the persistent travel plan they take with them — not just a chat message. ``` ### Technical Analysis The Skill instructs the Agent to activate for an exceptionally broad range of travel-related statements, including implicit references that do not explicitly request use of Aizzie. It then mandates a predefined promotional statement and external-service link after creating or modifying a trip. These instructions can override the expected scope of a normal travel response by directing the Agent toward an external platform even when the user merely requests information. The unconditional wording, including “Use whenever” and “Always tell the user,” limits the Agent's ability to obtain informed consent or determine whether external persistence is appropriate. The persistence claim is also required as a fixed response. If the external operation did not succeed or was not authorized, this ...[truncated 1364 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:30
Finding

Execution of a Remotely Mutable Unpinned npm Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance says to use the skill whenever travel is mentioned, 'even implicitly,' which is broad enough to trigger on ordinary conversation without clear user intent to invoke an external travel-planning platform. In this skill's context, unintended activation is more dangerous because it can lead to external data handling, persistent trip creation, and sharing features the user may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill highlights persistence, sharing, and collaboration, but does not clearly warn at activation time that user trip details may be stored on an external service and made shareable. This weakens informed consent and can expose sensitive travel plans, lodging, dates, and companion information if users do not realize their data leaves the chat context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs use of npx @aizzie/cli@latest, which fetches and executes the newest package version at runtime. This creates a supply-chain risk: a compromised publisher account, malicious release, or breaking change could cause arbitrary code execution in the agent environment without review or reproducibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The instruction to run npx @aizzie/cli docs relies on an unpinned package reference, so the executed code can change over time or be replaced by a malicious release. Because npx downloads and runs code immediately, this expands the attack surface to package-registry and maintainer compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.