Back to skill

Security audit

Austria

Security checks for vulnerabilities and agentic risk

Overview

This Austria travel-planning skill is coherent and scoped, with its main caveat being local trip memory that users should know is saved and reused.

Before installing, understand that the skill keeps Austria trip preferences in ~/austria/memory.md and may reuse them later. Review or delete that file if the device is shared, and verify current entry, customs, ETIAS, weather, and transport rules with official sources before booking or crossing borders.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger scope is overly broad: "what they can bring, how cash rules work, or whether neighboring-country hops are frictionless" can match many general travel questions and may cause the skill to activate outside a narrowly defined customs/border context. In a travel assistant, overbroad invocation increases the chance of users receiving incomplete or jurisdiction-sensitive customs guidance as if it were authoritative, especially for regulated goods, declarations, or cross-border movement.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · budget-and-costs.md (reported line 38)May include surrounding context.

md
- Assuming "no border" means no rules.
- Carrying large cash without understanding declaration duties.
- Packing restricted foods for alpine days without checking origin-country rules.
- Forgetting separate vignette or toll logic when a route crosses multiple countries by car.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · customs-and-border.md (reported line 29)May include surrounding context.

md
- Assuming "no border" means no rules.
- Carrying large cash without understanding declaration duties.
- Packing restricted foods for alpine days without checking origin-country rules.
- Forgetting separate vignette or toll logic when a route crosses multiple countries by car.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · winter-ski-and-christmas.md (reported line 32)May include surrounding context.

md
- Assuming "no border" means no rules.
- Carrying large cash without understanding declaration duties.
- Packing restricted foods for alpine days without checking origin-country rules.
- Forgetting separate vignette or toll logic when a route crosses multiple countries by car.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create a persistent local memory file for user trip data without any user-facing disclosure or consent. This creates a privacy risk because travel preferences, constraints, and potentially sensitive details can be retained across sessions unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The returning-user flow says to read stored memory silently and reuse prior user data without informing the user that previous session data is being accessed. Silent reuse of persisted personal preferences and constraints undermines transparency and can expose sensitive information in shared or multi-user environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.