Back to skill

Security audit

Airbnb Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly designed for Airbnb operations, but its calendar-mutation procedure uses broad authenticated browser control with unsafe token and temporary-file handling for a live business account.

Review this carefully before installing in a production Airbnb environment. Only use it with a trusted local bridge, a logged-in account you own, short-lived or scoped tokens if possible, a private unique temp-file path, and a human approval process for every guest send or calendar/price change.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/calendar-mutation-procedure.md:20
Finding

Privileged ClawBridge bearer token transmitted over plaintext HTTP and exposed through command arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/calendar-mutation-procedure.md:52
Finding

Predictable shared temporary file permits browser-evaluation payload collision or substitution

Content
View full analysis
{ ... })()"}` — the write tool needs no shell escaping. 2. Then one clean curl per exec: `curl -s -X POST -H "Authorization: Bearer $CLAWBRIDGE_TOKEN" -H "Content-Type: application/json" -d @/tmp/eval.json http://host.docker.internal:3201/tools/browser/eval` ``` ### Technical Analysis The procedure recommends a fixed, globally predictable path, `/tmp/eval.json`, for a payload submitted to an endpoint that executes JavaScript inside an authenticated browser. In a multi-agent or multi-user runtime, independent operations can overwrite the same file. A malicious local actor with write access to the shared temporary directory may also attempt to replace the file between creation and use. Depending on the `write` tool's file-opening and symlink behavior, a pre-created symbolic link could additionally redirect the write or cause unintended file modification. This is a time-of-check/time-of-use integrity problem: the payload the agent intends to execute is not cryptographically or mechanically bound to the payload eventually read by `curl`. Because `/tools/browser/eval` executes the supplied script in a logged-in browser context, payload substitution has materially greater impact than corruption of an ordinary temporary data file. ### Attack Path 1. An approved mutation causes the agent to prepare `/tmp/eval.json`. 2. Another agent or local attacke ...[truncated 1604 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CHANGELOG.md (reported line 30)May include surrounding context.

md
and a **Completion rule** (a MUTATE-CAL turn must end with a report or an
  explicit unconfirmed/failure statement; NO_REPLY forbidden).
- v0.2.1: `references/calendar-mutation-procedure.md` — added a
  **Transport rule**: ClawBridge calls go through exec + curl ONLY; the built-in
  `fetch`/`web_fetch` tool can't send the Authorization header and internal
  hosts are blocked for it — it killed two live runs on 2026-07-04 at the
  verification step (agents drift to it under pressure; now explicitly

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

md
`send_reply` is the only guest-messaging write, and it internally enforces
read → draft → approve → send-once → verify → report. Agents must not decompose
it into lower-level steps to skip verification. Calendar mutation (MUTATE-CAL) is
not a command verb here — it is the separate, approval-gated procedure in
`references/calendar-mutation-procedure.md` (see "Approved calendar mutations
(v0.2)"), which follows the same read → approve → do-once → verify → report shape.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
# Example — `check_inbox`

A READ operation. No approval, no write. Goal: surface threads needing attention,
prioritized, without changing anything.

> Tool names below are from the reference deployment. Map them via

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/check-inbox.md (reported line 3)May include surrounding context.

md
# Example — `check_inbox`

A READ operation. No approval, no write. Goal: surface threads needing attention,
prioritized, without changing anything.

> Tool names below are from the reference deployment. Map them via

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/calendar-mutation-procedure.md (reported line 12)May include surrounding context.

md
# Example — `check_inbox`

A READ operation. No approval, no write. Goal: surface threads needing attention,
prioritized, without changing anything.

> Tool names below are from the reference deployment. Map them via

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/calendar-mutation-procedure.md (reported line 54)May include surrounding context.

md
## Payload rule — NEVER inline JS into a quoted `-d` argument

The eval scripts below are full of single quotes. Wrapping them in `curl -d '...'`
breaks shell quoting (curl exits 3 "URL malformed" — observed live 2026-07-04, seven
consecutive failures). Instead, for EVERY `/tools/browser/eval` call:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/calendar-mutation-procedure.md (reported line 120)May include surrounding context.

md
- A ✓ Done response does NOT mean the UI registered the interaction — only the
  side panel opening / radio flipping / fresh-load label proves anything.
- Success claims without the Step-5 fresh-load check are the #1 failure mode.
- Inlining eval JS into `curl -d '...'` mangles shell quoting — always use the
  write-file + `-d @file` pattern (see Payload rule above).
- Using the built-in `fetch`/`web_fetch` tool for ClawBridge endpoints always
  fails (no auth header, internal host blocked) — exec + curl only (see

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/calendar-mutation-procedure.md (reported line 6)May include surrounding context.

md
> ⚠️ **THIS CHANGES LIVE PRODUCTION INVENTORY.** Every step below alters the real
> Airbnb listing: blocking a date removes a night from sale; opening one exposes
> it; a price change is live to every guest immediately. There is no "preview"
> and no reliable undo beyond the stated inverse operation. **Do NOT run any step
> of this procedure exploratorily, to "see what happens", or on your own
> initiative.** It executes ONLY under the MUTATE-CAL gate in `SKILL.md` →
> "Approved calendar mutations (v0.2)": the operator named the exact date(s)/field

Static analysis

No suspicious patterns detected.