T09 · Insecure Skill Coding Practices
- Location
SKILL.md:61- Finding
Agent-Facing Booking API Accepts Raw Payment Card and Sensitive Identity Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–63; related conflicting guidance at lines 88–89
Vulnerability Type: Plaintext sensitive-data handling in an Agent-accessible API workflow
Risk Level: HighVulnerable Code Snippet
markdown - **POST /api/v1/flights/book** — place booking request (zooz credit card flow). Body: `{ bookingToken, passengers: [{firstName, lastName, email, phone, birthday, title, nationality?, documentNumber?, documentExpiry?}], payment?: {cardNumber, expiry, cvv, holderName, currency?} }` Returns: `{ action, bookingId, providerReference, totalPrice, message }`The following safety instructions conflict with the booking request schema:
markdown ## Safety - Do not request user account passwords, OTPs, or payment credentials. - Ask before any booking-related action.Technical Analysis
The booking API schema permits raw card numbers, expiration dates, CVVs, names, contact information, birth dates, nationalities, and travel-document information to be included directly in an Agent-generated API request.
This design places highly sensitive payment and identity information within the Agent and tool-call data path. Depending on the host environment, those values may become visible in conversation history, tool traces, application telemetry, debugging output, proxy logs, or API request logs. CVVs are especially sensitive authentication data and should not be stored after authorization.
The documentation does not define a hosted checkout, client-side tokenization, secure secret-input channel, field-level redaction, retention policy, or logging prohibition. It also contains contradictory instructions: the booking schema accepts payment credentials, while the Safety section prohibits requesting them. An Agent attempting to satisfy the booking contract may therefore collect information that another instruction says it must not request.
Explicit approval before booking is an important transac ...[truncated 1993 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove raw card fields from the Agent API
- Delete
cardNumber,expiry, andcvvfrom the Agent-facing request schema. - Never require payment credentials to appear in prompts, conversation history, tool arguments, or model-visible state.
- Delete
-
Use hosted checkout or tokenization
- Have the booking endpoint return a short-lived, single-use hosted checkout URL.
- Alternatively, collect payment details through a PCI-compliant payment-provider component and send only an opaque payment token to Aerobase.
- Bind the token to the booking, amount, currency, user session, and short expiration period.
-
Minimize passenger information
- Request only fields strictly required by the airline or provider for the selected itinerary.
- Defer passport or document collection until it is demonstrably required.
- Use a secure user interface rather than conversational input for identity-document fields.
-
Prevent sensitive-data retention
- Redact payment and identity fields from application logs, HTTP traces, telemetry, exceptions, analytics, and support tooling.
- Disable request-body logging on booking endpoints.
- Define strict retention and deletion policies for passenger information.
- Encrypt necessary personal data in transit and at rest with access-controlled keys.
-
Resolve the contradictory instructions
- Retain the prohibition on asking for payment credentials.
- Update the booking workflow to explain that the Agent may initiate booking only after explicit approval, after which the user completes payment through a secure external checkout.
- Distinguish clearly between validating an offer, creating a pending booking, and authorizing payment.
-
Harden transaction authorization
- Display the final itinerary, passenger names, total price, currency, cancellation terms, and provider before requesting confirmation.
- Use an explicit, transaction-specific confirmation ...[truncated 170 chars]
-
