Back to skill

Security audit

Aerobase Travel Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its travel-planning purpose, but it also instructs automatic recurring deal checks using the user's home airport without clear opt-in or stop controls.

Install only if you are comfortable giving Aerobase an API key and sending travel details to its service. Treat recovery commitments and multi-leg itineraries as sensitive, and avoid enabling or relying on automatic deal monitoring unless you have an explicit way to opt in, set its frequency, and turn it off.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Score a specific flight for jetlag impact given exact departure and arrival times.

bash
curl -s -X POST "https://aerobase.app/api/v1/flights/score" \
  -H "Authorization: Bearer $AEROBASE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

Search flights on a route ranked by jetlag score. Pro tier returns up to 50 results.

bash
curl -s -X POST "https://aerobase.app/api/v1/flights/search" \
  -H "Authorization: Bearer $AEROBASE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

Search award flight availability across 24 loyalty programs with jetlag scoring.

bash
curl -s -X POST "https://aerobase.app/api/v1/awards/search" \
  -H "Authorization: Bearer $AEROBASE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

Compare 2-10 flights side by side with a recommendation.

bash
curl -s -X POST "https://aerobase.app/api/v1/flights/compare" \
  -H "Authorization: Bearer $AEROBASE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The recovery-plan endpoint can transmit more sensitive travel context, including exact itinerary timing and optional arrival commitments such as meetings or dinners. That expands the privacy risk because the skill may send schedule and behavioral data to a third-party service without any embedded warning, minimization guidance, or consent language.

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

Generate a personalized jetlag recovery plan with pre-flight, in-flight, and post-arrival schedules. Optionally assess risk against arrival commitments.

bash
curl -s -X POST "https://aerobase.app/api/v1/recovery/plan" \
  -H "Authorization: Bearer $AEROBASE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

Itinerary analysis sends a multi-leg travel history to the external API, which can reveal detailed movement patterns over time. In a travel skill this is functionally relevant, but the cumulative sensitivity is higher than simple single-flight lookup and warrants stronger disclosure and minimization controls.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

Analyze a multi-leg itinerary for cumulative jetlag fatigue, compounding effects, and recovery gaps.

bash
curl -s -X POST "https://aerobase.app/api/v1/itinerary/analyze" \
  -H "Authorization: Bearer $AEROBASE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells the agent to periodically query deals using the user's home airport and proactively surface results, but it does not require notice or consent before repeated external requests using user-associated travel data. This creates a privacy and transparency problem because location/travel preference data may be transmitted and processed without an informed, contemporaneous user action.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs periodic or session-start deal checks without tying them to a fresh user request or consent boundary. That can cause unintended background network access, surprise API usage, and autonomous behavior that exceeds normal user expectations for a travel-planning skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.