Back to skill

Security audit

Travel Customizer

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a Feishu travel lead-capture integration, but its public skill instructions do not match the implemented tool and it can send personal travel/contact details to a third-party table without enforced confirmation.

Review this before installing. It should be treated as a Feishu lead-capture tool, not a complete itinerary CRUD assistant. Only use it with a Feishu app/table you control, restrict table collaborators, make users explicitly confirm the exact data being submitted, and avoid collecting unnecessary sensitive details until the skill's documentation and implementation are aligned.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
tools.py:28
Finding

Customer PII Is Transmitted Without Enforced Confirmation or Data Masking

Content
View full analysis

Vulnerability Details

File Location: tools.py:28-88
Related Documentation: README.md:7-10, README.md:37-39
Vulnerability Type: Missing consent enforcement and unimplemented privacy controls
Risk Level: Medium

Complete Code Snippet

python
def submit_to_feishu(
    name: str,
    phone: str,
    destination: str,
    people_count: int,
    departure_date: Optional[str] = "",
    budget: Optional[float] = 0.0,
    preferences: Optional[List[str]] = None,
    special_requirements: Optional[str] = ""
) -> Dict[str, Any]:
    """
    ClawHub tool function: submits travel requirements to a Feishu multidimensional table.
    """
    app_id = os.getenv("FEISHU_APP_ID")
    app_secret = os.getenv("FEISHU_APP_SECRET")
    base_token = os.getenv("FEISHU_BASE_TOKEN")
    table_id = os.getenv("FEISHU_TABLE_ID")

    missing_configs = []
    if not app_id: missing_configs.append("FEISHU_APP_ID")
    if not app_secret: missing_configs.append("FEISHU_APP_SECRET")
    if not base_token: missing_configs.append("FEISHU_BASE_TOKEN")
    if not table_id: missing_configs.append("FEISHU_TABLE_ID")

    if missing_configs:
        return {
            "status": "error",
            "message": f"Missing Skill configuration: {', '.join(missing_configs)}"
        }

    try:
        token = get_tenant_access_token(app_id, app_secret)

        fields = {
            "Name": name,
            "Contact phone": phone,
            "Intended destination": destination,
            "Number of travelers": people_count
        }

        if departure_date:
            fields["Expected departure date"] = departure_date

        if budget and budget > 0:
            fields["Budget per person"] = budget

        if preferences and len(preferences) > 0:
            fields["Travel preferences"] = preferences

        if special_requirements:
            fields["Special r
...[truncated 3011 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add an explicit confirmation parameter backed by trusted agent state, rather than relying only on natural-language instructions:
    python
    if confirmed is not True:
        return {
            "status": "confirmation_required",
            "message": "Explicit user confirmation is required before submission."
        }
    
  2. Do not allow prompt-controlled text alone to manufacture the confirmation state. The orchestration layer should set it only after presenting the exact data and receiving an affirmative response.
  3. Mask telephone numbers in conversational output and logs. If the complete number is operationally necessary in Feishu, clearly disclose that it will be stored unmasked.
  4. Collect only fields required for the stated business purpose. Make optional fields opt-in and warn users before accepting sensitive details in special_requirements.
  5. Add type, length, and format validation for phone numbers, dates, traveler counts, budgets, preferences, and free-form text.
  6. Document the destination, intended recipients, retention period, deletion process, and whether the Feishu table is shared with third parties.
  7. Restrict the Feishu application and table collaborators to the minimum roles required to create and process these records.
  8. Either implement the README’s claimed masking behavior or remove the claim so users are not given an inaccurate privacy assurance.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:36
Finding

Declared Skill Tools Do Not Match the Executable Tool Interface

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:36-41
Related Implementation: tools.py:28-108
Vulnerability Type: Security-relevant specification and implementation mismatch
Risk Level: Low

Complete Code Snippet

The Skill specification declares the following interface:

text
Available tools:
- create_itinerary(destination, days, budget, preferences): Create a new itinerary.
- search_itinerary(keyword): Search itineraries.
- update_itinerary(record_id, updates): Update itinerary details.
- delete_itinerary(record_id): Delete an itinerary.

The implementation instead exposes the following function:

python
def submit_to_feishu(
    name: str,
    phone: str,
    destination: str,
    people_count: int,
    departure_date: Optional[str] = "",
    budget: Optional[float] = 0.0,
    preferences: Optional[List[str]] = None,
    special_requirements: Optional[str] = ""
) -> Dict[str, Any]:
    """
    ClawHub tool function: submits travel requirements to a Feishu multidimensional table.
    This function name is directly referenced by the definition in SKILL.md.
    """

The displayed prose and docstring are English translations of the audited source.

Technical Analysis

SKILL.md states that the Skill provides create, search, update, and delete operations for travel itineraries. None of the four named functions exists in tools.py. Conversely, the implemented submit_to_feishu function collects a customer’s name and telephone number and writes a lead record to Feishu, but this function and its PII-related behavior are not declared in SKILL.md.

The implementation’s docstring also incorrectly states that submit_to_feishu is referenced by SKILL.md. This mismatch prevents users and agents from accurately understanding the side effects and data requirements of the executable tool.

Although this is not tool replacement or runtime API spoofing, i ...[truncated 1541 chars]

Remediation
View remediation

Remediation Suggestions

  1. Choose one coherent declared purpose and make the specification and implementation match it.
  2. If lead submission is the intended functionality, replace the nonexistent CRUD declarations with the exact submit_to_feishu signature and explicitly disclose every category of personal data sent to Feishu.
  3. If itinerary CRUD is the intended functionality, implement the four documented functions and remove or separately document the lead-submission function.
  4. Document network destinations, authentication requirements, write operations, and user-visible side effects for every exposed tool.
  5. Add automated interface tests that parse the declared tool names and verify that matching callable functions exist with compatible parameters.
  6. Add integration tests confirming that each declared operation performs only its documented Feishu action.
  7. Correct the inaccurate submit_to_feishu docstring and version the Skill metadata when changing the public interface.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tainted flow: 'url' from os.getenv (line 85, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · tools.py (reported line 16)May include surrounding context.

python
"app_secret": app_secret
    }
    try:
        resp = requests.post(url, json=payload, timeout=10)
        resp.raise_for_status()
        data = resp.json()

Tainted flow: 'url' from os.getenv (line 85, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · tools.py (reported line 94)May include surrounding context.

python
"records": [{"fields": fields}]
        }
        
        resp = requests.post(url, headers=headers, json=payload, timeout=10)
        resp.raise_for_status()
        result = resp.json()

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior claims itinerary generation, querying, updating, and deletion, but the static findings indicate the implementation does not actually provide those capabilities and may instead only collect or submit travel data. This is dangerous because users may disclose sensitive personal travel details under false assumptions about how the skill works, and operators may approve a skill whose real behavior differs materially from its description.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tools.py (reported line 9)May include surrounding context.

python
FEISHU_API_BASE = "https://open.feishu.cn/open-apis"

def get_tenant_access_token(app_id: str, app_secret: str) -> str:
    """获取飞书 Tenant Access Token"""
    url = f"{FEISHU_API_BASE}/auth/v3/tenant_access_token/internal"
    payload = {
        "app_id": app_id,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes collecting names and phone numbers and storing them in Feishu Bitable, but it does not clearly warn users or installers that personal data will be transmitted to a third-party platform for storage and follow-up. This creates a transparency and privacy-consent gap, especially because the skill is explicitly designed to gather identifiable customer travel information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises tool-backed behavior that necessarily involves environment variables and network access, but it does not declare any explicit tool scope or permission boundaries. This weakens transparency and reviewability, making it harder for users and platforms to understand what resources the skill can access and increasing the chance of over-privileged execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill asks users to provide travel details and states that data will be written to Feishu Bitable, but it does not clearly warn that personal information will be transmitted to a third-party service. Travel itineraries can reveal sensitive personal data such as destinations, dates, preferences, and potentially budget or companion information, so lack of disclosure creates privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly includes record deletion functionality but does not warn users about irreversible or destructive data loss. In a travel-planning context, accidental deletion could remove itinerary history or planning data without the user understanding the consequence, especially if deletion is triggered through natural-language instructions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools.py (reported line 16)May include surrounding context.

python
"app_secret": app_secret
    }
    try:
        resp = requests.post(url, json=payload, timeout=10)
        resp.raise_for_status()
        data = resp.json()

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a broader itinerary assistant that can generate, query, and manage travel plans. In this file, the implemented behavior is limited to collecting user fields and creating a new remote record in Feishu; there is no itinerary generation, querying, or management logic present.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This call sends user-supplied personal and trip data to an external Feishu service. In context, the transmission itself is intended, but it becomes a real security/privacy issue because the code lacks visible consent, disclosure, and data-minimization safeguards for sensitive traveler information.

Content

Scanner excerpt · tools.py (reported line 94)May include surrounding context.

python
"records": [{"fields": fields}]
        }
        
        resp = requests.post(url, headers=headers, json=payload, timeout=10)
        resp.raise_for_status()
        result = resp.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool transmits personally identifiable information such as name, phone number, destination, dates, budget, and special requirements to a third-party SaaS platform without any explicit user-facing consent, notice, or data-handling disclosure in the tool itself. In a travel-assistant context, this is more sensitive because the data can reveal identity, plans, and preferences, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified as requests>=2.28.0, which allows installation of many future or older-yet-still-matching releases without guaranteeing a reviewed version. This weakens reproducibility and can expose deployments to known or newly introduced vulnerable releases of requests or its transitive dependency set.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Because requests is not pinned, it is impossible to verify from this manifest whether the installed version is affected by any of the known advisories associated with the package. In a travel-planning skill that may call external APIs and handle tokens or user itinerary data, an affected requests release could increase risk of credential leakage, TLS/verification issues, or other client-side security flaws.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Several user-facing messages and comments are written only in Chinese, including error and success responses returned by the function. The file does not indicate that the skill is intentionally region-specific or provide any user opt-in or language selection, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.