Back to skill

Security audit

Aerobase Travel Hotels

Security checks for vulnerabilities and agentic risk

Overview

This hotel skill is mostly coherent, but it exposes booking cancellation, rebooking, amendment, and voucher actions without equally clear confirmation rules for each high-impact change.

Install only if you trust Aerobase with hotel-search and booking-management authority. Before using it for anything beyond search, require the agent to show the exact booking, policy, fees, and action being taken, and get explicit confirmation for cancellations, rebooks, amendments, voucher redemptions, and payments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The skill exposes a destructive cancellation endpoint and related booking-management actions, but the surrounding controls rely mainly on natural-language guidance rather than enforced authorization or confirmation gates. If an agent supplies a wrong booking ID, acts on ambiguous user intent, or is prompted into misuse, it could cancel or modify reservations and cause financial loss or travel disruption.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
Payment methods: `ACC_CREDIT_CARD` (sandbox-safe), `TRANSACTION_ID`, `WALLET`, `CREDIT`
3. **GET /api/v1/hotels/bookings?guestId=...** or `?clientReference=...` — List bookings
4. **GET /api/v1/hotels/bookings/{id}** — Booking detail + cancellation policy
5. **DELETE /api/v1/hotels/bookings/{id}** — Cancel booking

## Booking Amendments

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- Base URL: `https://aerobase.app`
- Required env var: `AEROBASE_API_KEY`
- Auth header (preferred): `Authorization: Bearer ${AEROBASE_API_KEY}`
- Never ask users for passwords, OTPs, cookies, or third-party logins.
- Never print raw API keys in output; redact as `sk_live_***`.

### Request rules

Static analysis

No suspicious patterns detected.