Back to skill

Security audit

Aerobase Travel Flights

Security checks for vulnerabilities and agentic risk

Overview

This flight skill is mostly coherent, but it under-discloses booking authority and exposes raw payment card and passenger identity data in an agent-facing API workflow.

Review before installing if you may use the booking features. Flight search and comparison are straightforward, but do not enter payment card numbers, CVVs, passport details, or other sensitive identity data through an agent chat unless the provider supplies a secure checkout or tokenized payment flow and clear data-handling guarantees.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:61
Finding

Agent-Facing Booking API Accepts Raw Payment Card and Sensitive Identity Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–63; related conflicting guidance at lines 88–89
Vulnerability Type: Plaintext sensitive-data handling in an Agent-accessible API workflow
Risk Level: High

Vulnerable Code Snippet

markdown
- **POST /api/v1/flights/book** — place booking request (zooz credit card flow).
  Body: `{ bookingToken, passengers: [{firstName, lastName, email, phone, birthday, title, nationality?, documentNumber?, documentExpiry?}], payment?: {cardNumber, expiry, cvv, holderName, currency?} }`
  Returns: `{ action, bookingId, providerReference, totalPrice, message }`

The following safety instructions conflict with the booking request schema:

markdown
## Safety

- Do not request user account passwords, OTPs, or payment credentials.
- Ask before any booking-related action.

Technical Analysis

The booking API schema permits raw card numbers, expiration dates, CVVs, names, contact information, birth dates, nationalities, and travel-document information to be included directly in an Agent-generated API request.

This design places highly sensitive payment and identity information within the Agent and tool-call data path. Depending on the host environment, those values may become visible in conversation history, tool traces, application telemetry, debugging output, proxy logs, or API request logs. CVVs are especially sensitive authentication data and should not be stored after authorization.

The documentation does not define a hosted checkout, client-side tokenization, secure secret-input channel, field-level redaction, retention policy, or logging prohibition. It also contains contradictory instructions: the booking schema accepts payment credentials, while the Safety section prohibits requesting them. An Agent attempting to satisfy the booking contract may therefore collect information that another instruction says it must not request.

Explicit approval before booking is an important transac ...[truncated 1993 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove raw card fields from the Agent API

    • Delete cardNumber, expiry, and cvv from the Agent-facing request schema.
    • Never require payment credentials to appear in prompts, conversation history, tool arguments, or model-visible state.
  2. Use hosted checkout or tokenization

    • Have the booking endpoint return a short-lived, single-use hosted checkout URL.
    • Alternatively, collect payment details through a PCI-compliant payment-provider component and send only an opaque payment token to Aerobase.
    • Bind the token to the booking, amount, currency, user session, and short expiration period.
  3. Minimize passenger information

    • Request only fields strictly required by the airline or provider for the selected itinerary.
    • Defer passport or document collection until it is demonstrably required.
    • Use a secure user interface rather than conversational input for identity-document fields.
  4. Prevent sensitive-data retention

    • Redact payment and identity fields from application logs, HTTP traces, telemetry, exceptions, analytics, and support tooling.
    • Disable request-body logging on booking endpoints.
    • Define strict retention and deletion policies for passenger information.
    • Encrypt necessary personal data in transit and at rest with access-controlled keys.
  5. Resolve the contradictory instructions

    • Retain the prohibition on asking for payment credentials.
    • Update the booking workflow to explain that the Agent may initiate booking only after explicit approval, after which the user completes payment through a secure external checkout.
    • Distinguish clearly between validating an offer, creating a pending booking, and authorizing payment.
  6. Harden transaction authorization

    • Display the final itinerary, passenger names, total price, currency, cancellation terms, and provider before requesting confirmation.
    • Use an explicit, transaction-specific confirmation ...[truncated 170 chars]
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation claims the skill is 'API-only' with 'no user credential collection,' but later defines a booking flow that accepts full passenger PII and payment card data, including CVV. This contradiction can cause operators to treat the skill as low-risk while it actually handles highly sensitive financial and identity data, creating elevated risk of unsafe collection, logging, storage, or transmission practices.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest advertises only search, comparison, and scoring, but the body also exposes booking and booking-management capabilities. This scope mismatch can mislead users, reviewers, or policy systems into approving a skill with higher-risk transactional behavior than its declared purpose, increasing the chance that sensitive operations are invoked without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- Base URL: `https://aerobase.app`
- Required env var: `AEROBASE_API_KEY`
- Auth header (preferred): `Authorization: Bearer ${AEROBASE_API_KEY}`
- Never ask users for passwords, OTPs, cookies, or third-party logins.
- Never print raw API keys in output; redact as `sk_live_***`.

### Request rules

Static analysis

No suspicious patterns detected.