Back to skill

Security audit

Travel Plan-Journione

Security checks for vulnerabilities and agentic risk

Overview

This travel-planning skill sends confirmed itinerary details to JourniOne and optional travel-search services, but those data flows are disclosed, purpose-aligned, and gated by user travel or booking intent.

Install only if you are comfortable sending confirmed itinerary details and approved images or extracted document text to JourniOne to create a public read-only preview link. Do not include passports, precise home addresses, health information, or private photos unless you have intentionally removed sensitive content. Hotel, flight, booking, payment, cancellation, and account-editing actions should be treated as separate decisions and confirmed before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
耗时与提交按 [持续更新与 Preview 交付](playbooks/preview-progress.md) 执行。普通生成可直接运行 `scripts/submit-poster-request.mjs`,提交已冻结的请求文件并显示真实等待时长;验证接受响应后立即交付实际 Preview,不等待地图和生图。准备阶

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
5. 用 `scripts/prepare-poster-request.mjs` 从 JSON 输入生成确定性请求文件;它只校验和组装,不联网、不调用模型。服务状态与活动状态分开:服务计划建议用 suggested、已暂选用 selected,不能写 planned;地点名与活动描述分开,脚本将已有 location

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
**Travel Journal 行程卡、实际 Preview 主链接、Google Maps 逐日路线与点位**。支持对话内可视化时调用 [固定卡片脚本](scripts/render-roadbook-card.mjs),否则使用完整 Markdown 卡片;不可退化为仅给裸链接。实际封面未就绪时立即使用自带封面

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill hardcodes Chinese-language default opening and interaction behavior without clear opt-in or language negotiation. While not a direct exploit primitive, this can mis-handle user intent, produce misleading consent/confirmation flows, and increase the risk that users approve actions or disclosures they do not fully understand.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is configured to auto-trigger on very broad, common travel-related phrases such as wanting to go out, asking how to visit a city, or adjusting an itinerary. This can cause the skill to activate without clear user intent, leading to unsolicited collection, processing, and possible external transmission of travel preferences, itinerary data, and attachments into downstream services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to send user travel and lodging search parameters to an external service endpoint (api.tourmind.com), including dates, occupancy, room configuration, and preference data. This is a real data-transmission boundary; if activation or consent is mishandled elsewhere in the skill, user itinerary and potentially sensitive travel metadata can be disclosed to a third party.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
若已安装或可调用 `tourmind-booking`,用户已要求按路线推荐、主选区域已按路线确定,且位置、入住、退房、每房成人数与房间数已按继承与估算规则补齐,立即用住宿搜索包调用它获取实时酒店推荐,不再追问“是否需要查酒店”。若只缺一项会阻塞搜索的入住配置,先补问该项,得到答案后继续调用。酒店名称、坐标、房型、图片、价格、取消政策与可订状态只采用 TourMind 返回值;区域研究本身不编造酒店或实时价格。确认该 Skill 不可用后,按依赖准备流程当轮给出安装或重载步骤,保留完整住宿搜索包;恢复后继续已授权查询,未恢复时明确尚无实时结果。实时酒店发现可以在最终行程确认前进行,因为选定酒店会成为路线锚点;创建订单、付款和取消仍必须单独确认,且不得阻塞 JourniOne 第一阶段交付。

酒店查询依赖当前可用的官方 `tourmind-booking` 及其实际接口契约,执行前读取 [TourMind 查询依赖](references/tourmind-query-dependency.md) 与该 Skill 的参数指南。无凭证时通过宿主 HTTPS 直接使用 `https://api.tourmind.com/skill/toc/*` 公开通道查询酒店、详情、实时报价和验价,不要求 Token、登录、注册或额外 TourMind MCP;已有 `uk_` / `sk_` 凭证按官方个人 / 企业通道处理,订单操作仍需认证与相应授权。

TourMind 按当前官方策略保留完整候选池,以单店或批量实时报价逐店核验并选出最多 5 家;JourniOne 首次向用户返回酒店结果时,每个住宿段只展示排名第一的首选,不同时铺开另外四家。首选必须包含当前房型与价格口径、取消政策、库存状态、距离和两三条可验证理由;另外四家连同搜索输入、排序、核验时间和 TourMind 链接只缓存在当前任务的住宿搜索包中,不在首次回复泄露名称或列表页。用户追问“更多选择、另一家、便宜一点、近一点”等时,再按原排序或新偏好返回缓存候选;搜索条件变化或报价失效时先重新查询。详细缓存与失效规则见 [references/accommodation-area-and-hotel-handoff.md](references/accommodation-area-and-hotel-handoff.md)。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown playbook forces a specific language/locale in its natural-language instructions, which can violate language-choice policy when no user opt-in is provided. The file does not state that it is only for Chinese-speaking users or otherwise justify the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The playbook’s natural-language instructions are exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or justification is provided. The file does not indicate that this skill is limited to Chinese-speaking users or that language selection is configurable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file mandates Chinese-language interaction content throughout the skill guidance, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language policy concern because it effectively forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The playbook's natural-language instructions are entirely in Chinese, which can impose a language/locale constraint on users or operators without any opt-in mechanism. The file does not state that the skill is intended only for Chinese-speaking users or a China-specific workflow, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill is written as Chinese-only operational guidance and output templates, with no indication that the user may choose another language or that the skill is restricted to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill file is written in Chinese and provides no indication that another language may be used or that the language choice is optional. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese and does not indicate that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The contract binds display currency to conversation language when the user has not explicitly chosen a currency. This can misrepresent prices, create user confusion, and cause planning or booking decisions to be made on amounts shown in an inferred currency rather than a user-confirmed one. In a travel-planning skill, currency display directly affects perceived affordability, so silent inference is risky even if it does not alter source prices.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This clause reaffirms that Chinese-language queries force CNY as the display currency even when output language differs, preserving the same non-consensual language-to-currency mapping. Repeating the rule in snapshot behavior increases the chance the incorrect currency propagates consistently across cards, booking pages, H5, and PDF, amplifying user misunderstanding throughout the workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill file is written as a Chinese-only operational contract and includes field labels and instructions solely in Chinese, with no indication that users or operators may choose another language. Under the stated policy, forcing a specific language without opt-in is a natural-language locale violation unless the regional constraint is explicit and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains natural-language instructions that implicitly force outputs in Chinese, including mandated response wording and examples. Under the language/locale policy rule, a skill should not require a specific language unless it offers user choice or clearly documents a justified locale-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document is written as a Chinese-only skill contract and does not indicate that the user may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a justified locale constraint is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains operational instructions exclusively in Chinese, and nowhere indicates that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L026 sets "language": "zh" in the example request, and the document title/content consistently prescribe Chinese-language values as the default format. Because this is natural-language guidance rather than a clearly justified region-specific constraint, it can violate language/locale policy by forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L050 specifies "options": {"language": "zh", ...} as part of the contract example, reinforcing a fixed Chinese output locale. The file does not nearby clarify that this is only illustrative or that users may choose another language, so it reads as a forced locale requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file uses Chinese-only string literals for matching titles and for validation error messages, while also mixing in a few English travel terms. This creates a language/locale constraint in behavior and user-facing errors without any visible opt-in or justification that the skill is intentionally Chinese-only or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At L122, the skill rejects any language outside zh/en/fr/es, which is a natural-language locale restriction embedded in code. The file does not present this as an optional user choice or justify it as a region-specific constraint, so it fits the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file-level comments explicitly state that output is in Chinese, and the runtime progress/error messaging is also hard-coded in Chinese. This imposes a specific language on users without any opt-in or documented locale justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The progress labels shown to users are all fixed Chinese strings and there is no mechanism to select another language. Because the skill exposes these messages directly during execution, it violates the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.