Back to skill

Security audit

攒够了去旅行

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk, document-only travel-points skill, though one reference file broadens the concept into general reward suggestions.

Install this only if you want a lightweight Chinese travel-points journaling prompt. Be aware that one reference document mentions broader reward suggestions and reward-pool behavior, so users expecting a strictly travel-only tracker should review that scope. Confirm how the host stores point totals and history before using it with personal data.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The product principles redefine the skill as a broad 'reward yourself system' with a reward-pool recommendation flow, which materially exceeds the manifest's narrowly scoped travel-points logging and progress use cases. This scope drift is dangerous because it can cause the agent to trigger outside approved contexts, collect or infer extra behavioral data, and deliver functionality the user and platform did not authorize.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The instruction to proactively give three reward suggestions by default, support type-based generation, state matching, and adding items to a reward pool expands the skill into a general recommendation engine. In this skill context, that is risky because it encourages activation even when the user did not ask to log points or check travel-goal progress, undermining least-privilege behavior and manifest-based user expectations.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
State matching and reward-pool management are not necessary to fulfill the declared function of a travel-points reward skill, so they introduce unjustified behavioral inference and feature expansion. That makes the skill more dangerous because it may profile user mood, fatigue, spending preference, or motivation state without a clear need, increasing privacy and overreach risk.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
By stating that travel is not the only reward and that the product should span a full ladder of immediate and experiential rewards, the document broadens the skill beyond its travel-points-only framing. This mismatch is dangerous because it can steer the agent into unapproved recommendation behavior and make users believe they are interacting with a general self-reward system rather than a narrowly scoped points tracker.

Static analysis

No suspicious patterns detected.