Back to skill

Security audit

Letundra.com AI Travel Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Russian-language Letundra travel-information helper that fetches public Letundra pages or feeds, with no evidence of hidden persistence, credential theft, destructive behavior, or automatic privileged actions.

Install this if you want a Russian-language Letundra travel helper and are comfortable with the agent fetching public pages from letundra.com. Treat publish-all.sh as maintainer tooling: only run it if you intentionally want to publish skills with an authenticated ClawHub CLI session.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Описание заявляет пользовательский AI-скилл про путешествия, который должен отвечать на вопросы о визах, новостях, праздниках и валютах. Однако код не реализует никакой travel-функциональности, обработки пользовательских запросов, получения данных с letundra.com или логики ответов. Вместо этого он выполняет административную DevOps-задачу: публикует набор отдельных скиллов в ClawHub, проверяя наличие CLI и логин. Это materially different primary purpose и явные undeclared capabilities, поэтому налицо несоответствие описания и поведения.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Описание существенно шире фактического поведения. В коде нет логики для виз, праздников или валют, нет маршрутизации по соответствующим пользовательским запросам и нет доступа к каким-либо ресурсам кроме RSS-ленты новостей Letundra. Реальная основная функция — получение и форматирование новостей из RSS feed. Упоминание RSS и новостей соответствует коду, но заявленный общий travel-функционал materially overstated, поэтому это mismatch.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly instructs use of network access via web_fetch but does not declare any tool scope such as allowed tools, permissions, or domain restrictions. In agent environments, undeclared network capability weakens least-privilege controls and can enable broader outbound requests than users or platform policy expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description and usage instructions are written to use Russian-language resources by default, and the skill later hard-codes /ru/ URLs. This creates a locale constraint without documenting user choice or opt-in, which matches the policy category for language/locale violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples and URL table hard-code https://letundra.com/ru/... for all fetches, indicating the skill always uses the Russian locale. Because no alternative locale or user choice is provided, this is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file specifies the description, usage examples, workflow target URL, and output template entirely in Russian, which indicates the skill is intended to operate in a fixed language/locale. There is no indication that users can choose another language or that the Russian-only scope is explicitly justified as a locale-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description, usage examples, workflow instruction, and output format are all written in Russian, and the workflow hard-codes a /ru/ URL path. There is no indication that the skill is region-specific or that users may choose another language, which creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language description, usage examples, workflow text, output format, and failure message are all written only in Russian. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-facing natural language in the description and invocation examples is Russian, and the workflow hardcodes the /ru/ news path. This indicates a locale-specific behavior without any opt-in or explanation, which can violate language/locale policy for broader audiences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The "Когда использовать" section provides only a few example phrases like "Хочу подписаться на новости Таиланда" without explicit boundaries, exclusions, or a defined trigger list. This makes the skill's invocation scope ambiguous and could overlap with ordinary requests about news subscriptions rather than a specific RSS-generation action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script contains user-facing comments and console messages in Russian throughout, including status, errors, and instructions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes one universal travel-oriented skill named 'letundra' for answering visa, news, holiday, RSS, and currency questions. This script instead operates as a bulk publisher for five distinct skills ('letundra-visa', 'letundra-news', 'letundra-rss', 'letundra-holidays', 'letundra-currency'), indicating repository/package-management behavior rather than the described end-user skill behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A travel information skill would be expected to fetch or process travel-related data, but this script authenticates with ClawHub and publishes packages externally. Publishing artifacts to a marketplace is an administrative/release capability unrelated to answering user questions about visas, news, holidays, RSS, or currencies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTTP request sets Accept-Language to prefer ru-RU, which enforces a language/locale preference in the skill's behavior. The file also formats dates using ru-RU, and there is no user opt-in or documented region-specific justification for this constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The toLocaleDateString('ru-RU', ...) call hard-codes Russian output for all users. This is a natural-language policy issue because the skill does not provide a language choice or explain why Russian output is required.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest and usage sections describe a skill that fetches travel information from letundra.com via web_fetch. The project structure additionally advertises a local parser script (letundra_yandex.js), which implies extra executable/local processing capability beyond the stated user-facing scope of visas, news, holidays, RSS, and currency information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.