Back to skill

Security audit

Travel

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent travel-record skill, but it automatically reads and updates sensitive shared health, booking, finance, contact, vehicle, and travel-history files without clear per-change user approval.

Review this skill before installing if you do not want an agent to maintain a long-term local travel archive. It does not appear to exfiltrate data or run code, but it is designed to persist and update sensitive travel records automatically. Consider using it only with a clear habit of reviewing file changes, redacting booking locators where possible, and keeping health, contacts, and finance files access-controlled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
` ``` ```text Write the paperwork facts into the shared `~/Clawic/data/pets/<name>.md` ``` ```text Anything durable this table does not name | `~/Clawic/data/travel/<plural-noun>.md`, or `artifacts/<kebab-name>.md` ``` ### Technical Analysis The Skill constructs or follows filesystem paths derived from configuration entries, persistent `## Boxes` records, pet names, place names, provider names, and other user-controlled labels. It does not require canonicalization, path-separator filtering, traversal re ...[truncated 2022 chars]:38
Finding

Unvalidated Dynamic Paths Can Escape Declared Data Directories

Content
View full analysis
` ``` ```text Write the paperwork facts into the shared `~/Clawic/data/pets/.md` ``` ```text Anything durable this table does not name | `~/Clawic/data/travel/.md`, or `artifacts/.md` ``` ### Technical Analysis The Skill constructs or follows filesystem paths derived from configuration entries, persistent `## Boxes` records, pet names, place names, provider names, and other user-controlled labels. It does not require canonicalization, path-separator filtering, traversal rejection, or verification that the resolved path remains within the directories declared in `configPaths`. This conflicts with the Skill's claim that all reads and writes remain within its declared data directories. Values such as `../../Documents/private.md`, absolute paths, or symlinks that resolve outside an allowed directory could redirect an agent to unrelated local files. Persisted `## Boxes` entries are particularly sensitive because the Skill directs the agent to treat that index as authoritative and open referenced files when their conditions apply. A malicious or compromised entry could therefore trigger unintended file access in later sessions. ### Attack Path 1. An attacker influences a configuration value, filename-producing label, or persisted `## Boxes` entry. 2. The attacker supplies a path containing traversal components, an absolute path, or a path through a symlink. 3. A later request activates the relevant travel workflow. 4. The agent follows the Skill's instruction to read or write the derived path. 5. Because no co ...[truncated 856 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Plaintext Booking Locators Are Stored with Traveler Identity

Content
View full analysis
.md` ``` ```text date | type | provider | locator | travellers | status | free change/cancel until | amount with currency | trip ``` ```text The locator, exactly as issued. It is the only field that survives a provider changing its website. ``` ```markdown | Date | Type | Provider | Locator | Travellers | Status | Free change/cancel until | Amount | Trip | |------|------|----------|---------|------------|--------|--------------------------|--------|------| | 2026-09-12 | flight | BA | 4KJ2QP | A, B | confirmed | non-refundable | 1,180 EUR | 2026-japan | | 2026-09-14 | stay | Ryokan Kyoto | R-88213 | A, B | confirmed | 2026-09-07 23:59 JST | 640 EUR | 2026-japan | ``` ```text The locator is a working identifier and stays. The account password behind it never does. ``` ### Technical Analysis The Skill requires complete booking locators or confirmation codes to be retained in a shared plaintext Markdown file alongside the provider and traveler identity. For some airlines, hotels, and booking platforms, a booking locator combined with a traveler's surname or other readily available identity information is sufficient to access a manage-booking interface. Consequently, a locator may function as an access token rather than as an ordinary non-secret identifier. The storage policy categorically treats these values as safe to retain, while no encryption, restrictive filesystem permissions, masking, retention minimization, or secret-manager integration is required. The shared nature of `~/Clawic/data/bookings/` broadens exposure because other Skills or local processes may legitimately read the same directory. ### Attack Path 1. The Skill r ...[truncated 1280 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (23)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
---
name: Travel
slug: travel
version: 1.0.2
description: 'Runs a traveler''s standing system: dream list, passports and visas, Schengen day counts, bookings, points, budgets, and what broke last time. Use when someone names a destination they want to visit someday, when a passport, visa, ETA, or entry rule has to be checked before dates are fixed, when counting days already spent in a visa-limited region, when a reservation or cancellation deadline needs recording, when a flight is cancelled or delayed, a bag goes missing, a passport is stolen or a claim has to be filed, when deciding which destination to take next against a season and

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section directs broad post-event logging of vaccinations, allergies, medications, conditions, insurance policy details, receipts, and claims into shared files and artifacts. That creates a concentrated repository of highly sensitive health and financial information, increasing the blast radius of any memory exposure, prompt leakage, cross-skill access, or unauthorized retrieval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises extremely broad activation criteria spanning wishlist management, entry rules, bookings, disruptions, budgeting, health-adjacent concerns, and post-trip debriefs. In an agentic environment, such a wide trigger surface can cause the skill to engage on loosely related prompts and access multiple local data stores unnecessarily, increasing the chance of over-collection, unintended file reads, and incorrect routing of user tasks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The instruction to 'act-as the system of record' and 'write the archive without asking' authorizes durable state changes without explicit confirmation. Even though the skill says it will not execute transactions, silent writes to shared local notes can create privacy issues, propagate errors into future decisions, and let prompt-injected or misparsed content become persisted data across sessions.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
- The traveller is not a solo adult: children, a group splitting money, elderly parents, a pet, or a stay long enough to have legal consequences
- Coming home: what was actually spent, what to recommend, what to never pack again, what to claim
- Not for one trip's day-by-day itinerary (`travel-planning`), fare search (`flight`), accommodation search (`booking`), car hire (`car-rental`) or emigrating (`expat`) — this is the layer that outlives any single trip
- Mode: **act-as** the system of record (write the archive without asking) and **advise** on decisions. Never execute a transaction.

## Quick Reference

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs users to record people met during client visits in a shared contacts file and gives identity fields to store, but provides no privacy, consent, retention, access-control, or data-minimization guidance. In a business-travel context, this can cause unnecessary collection and broad sharing of personal data about clients or contacts, creating privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs reading a health profile for anyone with a medical constraint, but provides no warning that this is sensitive health information requiring stricter handling. In this travel context, health data may be broadly consulted during planning, increasing the chance of over-collection, unnecessary access, or propagation of medical details into other artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to store third-party contact details in a shared contacts file without any minimization, consent, retention, or access-control warning. Because this data concerns people who may not be the primary user, it creates a real privacy risk of unnecessary collection and persistence of personal information across trips and skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file instructs the skill to write names of people met into a shared contacts repository outside the trip dossier. That expands data collection beyond core travel recordkeeping and can store third-party personal data without clear necessity, consent, minimization, or access controls, creating privacy and cross-context data exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to create and update multiple local files containing travel, claims, and booking data without requiring explicit user confirmation before modifying persistent state. In an agent setting, this can lead to unintended data changes, privacy exposure, or corruption of user records, especially during a stressful disruption workflow where the model may act autonomously.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly instructs the agent to read a shared health profile containing vaccinations, allergies, medications, and conditions before answering medical questions, but this file does not pair that access with a clear user-consent or user-notification step. Because health data is highly sensitive, silent background retrieval increases the risk of over-collection, unintended disclosure in responses, or use beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent both to read sensitive health data from shared memory and to use configuration constraints, creating a workflow where protected medical information may be processed across responses without strong scoping guarantees. This is dangerous because persistent memory can cause sensitive data to be reused, exposed in later contexts, or retained longer than necessary for the travel task at hand.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to record generic medication names and related condition details in a shared health profile creates persistent storage of sensitive medical information. Even if intended to help with border crossings and refills, storing such data in shared memory raises confidentiality risks, especially if other skills, users, or future turns can access or infer it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L07 activates the guidance for very broad situations like 'before booking anything' or 'before buying insurance,' which are common travel-related actions without clear constraints or exclusions. The file does not provide specific trigger phrases or negative examples to limit when this skill should be invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill handles highly sensitive travel-related data including document metadata, health details, contacts, bookings, and insurance information, yet the description does not provide a clear privacy warning or consent boundary. Even though the template includes some secret-handling rules, users may still disclose sensitive personal data without understanding that it will be stored across persistent files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly authorizes automatic writes and deletions without user permission, with only a minimal one-line announcement. In a skill that manages durable personal records across multiple files, this creates a real risk of unauthorized modification, silent data loss, and cross-file corruption, especially because it also permits deletions in shared stores.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · money.md (reported line 33)May include surrounding context.

md
|---|---|
| `budget` | Dorms or the cheapest private room, self-catering or street food, public transport only, free sights |
| `midrange` | Mid-tier hotel or apartment, restaurants for one meal a day, occasional taxi, paid entries |
| `comfort` | Well-located hotel, restaurants without checking prices, taxis by default, guided days |

The multiplier between adjacent styles is typically around 2× on lodging and around 1.5× on the daily rate, and roughly nothing on transport — which is why "we could do this cheaply" rarely moves a long-haul total as much as expected.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to write recurring travel costs into a shared finances file outside the travel archive, which expands the write scope from travel notes into broader personal financial records. That creates a real integrity and privacy risk because the agent could modify unrelated finance data without explicit user consent or a clear boundary check.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs persistent writes of spend figures, refunds, and claims into multiple local files, including financial records, as an automatic follow-up action. Without explicit notice and confirmation, this can silently alter sensitive personal records, propagate mistakes across several files, and create privacy issues if the data is more detailed than the user intended to store.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file explicitly directs the agent to write travel-relevant facts into persistent vehicle records outside the immediate trip dossier. That expands data handling scope beyond transient trip assistance and can cause unauthorized cross-context retention of sensitive data such as vehicle identifiers, travel patterns, and destination-linked metadata without an explicit user request at the time of storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to write vehicle and trip details to persistent files occurs without any disclosure that sensitive travel data will be stored. Vehicle plates, cross-border use, and trip-linked facts are personal data that can reveal identity, routines, and assets, so silent persistence creates a privacy and scope-of-consent problem even if the storage is internal.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The post-trip instruction mandates saving pass calculations, transfer details, local transport rules, and driving quirks into memory files without warning the user. In context, these records can accumulate into a detailed travel history and behavior profile, making the persistence more dangerous than ordinary note-taking because it is automatic and cross-trip.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to persist changes to local travel records ('memory.md', 'destinations.md', and '## Due') after adding, ranking, or removing wishlist entries, but it does not require confirming with the user before modifying those files. In an agent setting, silent writes to persistent state can corrupt records, overwrite user-maintained data, or create privacy and integrity issues if triggered by ambiguous or malicious prompts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The instructions require updating reusable destination place files with local transport rules, transfer details, and driving quirks after trips. While operationally useful, this broadens the skill from trip support into persistent knowledge collection and can unintentionally store user-derived travel history or location-linked details beyond what the manifest clearly promises.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.