Back to skill

Security audit

travel-itinerary-builder

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed travel-itinerary generator with low-impact scope issues but no evidence of hidden access, persistence, credential handling, exfiltration, or destructive behavior.

Install this if you want Chinese self-contained HTML travel manuals. Be aware it may trigger on broad travel-related wording and may fetch public attraction images from Wikipedia for local use; review generated logistics against current official travel sources before relying on them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions are extremely broad, including generic words like “旅行”, “旅游”, “行程”, “攻略”, “itinerary”, and “travel plan”, which can cause the skill to activate for ordinary conversation not actually requesting itinerary generation. This creates an overreach/control-flow vulnerability at the orchestration layer: the skill may intercept unrelated requests and force HTML itinerary behavior, leading to incorrect handling, user confusion, and possible suppression of more appropriate skills.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill hard-codes Simplified Chinese output without checking the user’s language preference or documenting a strict locale constraint. While not a classic security flaw, this can cause unsafe or unusable outputs when users expect another language, especially for travel logistics where misunderstanding transport, timing, or safety instructions could degrade reliability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.