Back to skill

Security audit

LovTrip Meetup Planner

Security checks for vulnerabilities and agentic risk

Overview

This meetup-planning skill is coherent, but it asks users to run an unpinned external MCP package while handling sensitive location and schedule data with limited privacy guidance.

Review this skill before installing. Use a pinned, reviewed version of the LovTrip MCP package instead of `@latest` where possible, keep `AMAP_API_KEY` in a secret manager or private environment, and only submit participant locations, schedules, names, or calendar details after the people involved have agreed. Prefer coarse locations unless exact coordinates are needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16-25
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: High

json
{
  "mcpServers": {
    "lovtrip": {
      "command": "npx",
      "args": ["-y", "lovtrip@latest", "mcp"],
      "env": {
        "AMAP_API_KEY": "your-amap-api-key"
      }
    }
  }
}

Technical Analysis

The configuration invokes npx with the mutable dependency specification lovtrip@latest. The -y option suppresses the normal installation confirmation, causing the currently published version of the package to be downloaded and executed automatically.

Because latest is a mutable registry tag, the code executed at runtime may differ from the version that existed when this skill was reviewed. The project does not provide an exact package version, a lockfile, an integrity hash, or local source code for the MCP implementation. Consequently, the effective executable payload cannot be fully established from the audited files.

This creates a supply-chain trust boundary in which compromise of the package, its publisher account, or the package registry could cause arbitrary package lifecycle or runtime code to execute under the privileges of the user running the skill.

Attack Path

  1. An attacker compromises the lovtrip package publishing account, its release process, or the package distribution channel.
  2. The attacker publishes a malicious release and assigns it to the latest distribution tag.
  3. A user follows the documented configuration and starts the MCP server.
  4. npx -y lovtrip@latest mcp resolves and downloads the attacker-controlled release without interactive confirmation.
  5. Package lifecycle scripts or the package entry point execute locally with the privileges of the invoking user.
  6. The malicious package can access data and resources available to that process, including the configured `AMAP_AP ...[truncated 1020 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace lovtrip@latest with an exact, reviewed version, such as lovtrip@1.2.3. Do not use mutable tags or permissive version ranges for executable dependencies.
  2. Record and verify the package's cryptographic integrity using a lockfile or an equivalent checksum-verification mechanism.
  3. Document the expected registry, package publisher, source repository, and release-signing or provenance information so users can verify package authenticity.
  4. Prefer installing the reviewed dependency during a controlled setup phase rather than downloading code whenever the MCP server starts.
  5. Where practical, vendor the reviewed implementation or distribute a reproducible, signed artifact whose contents match the audited source.
  6. Disable package lifecycle scripts during installation unless they are explicitly required and independently reviewed.
  7. Run the MCP server in a restricted environment with minimal filesystem access, constrained outbound networking, and no unrelated credentials.
  8. Provide AMAP_API_KEY as a narrowly scoped secret, rotate it periodically, and ensure it is not exposed to other child processes or logs.
  9. Establish an update procedure that reviews new versions before changing the pinned dependency and its verified integrity metadata.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly processes sensitive participant data such as locations, schedules, and interests, and it references external web services and an MCP server, but it does not warn users that this information may be transmitted off-platform. In a meetup-planning context, location/time data can reveal home/work patterns and social relationships, so omission of a privacy/transmission warning creates a real risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example normalizes sending multiple participants’ location data, including precise coordinates, to several tools without any mention of consent, minimization, or privacy handling. In a meetup-planning skill, this can lead to unnecessary disclosure of sensitive location information for all participants, especially when exact coordinates are shared across map and weather services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill processes precise addresses and coordinates across multiple functions, including midpoint calculation, venue optimization, weather, and traffic checks, without any notice that sensitive location data may be transmitted to external services. In a multi-person meetup planner, this increases privacy risk because users may submit multiple individuals' locations, enabling inference of home/work areas and movement patterns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The reference explicitly supports exporting calendar events with attendee names, meeting time, and location into an iCal file, but it provides no warning or consent guidance about sharing personal schedule information. In a meetup-planning context, this can expose sensitive social graph, availability, and location data if users export or distribute calendar entries without realizing what personal data is embedded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The setup block requires an AMAP_API_KEY and shows how to place it in environment configuration, but provides no warning that the credential is sensitive or guidance on secure storage/rotation. This can lead users to hardcode, commit, or otherwise mishandle the key, resulting in unauthorized API use or account abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file's natural-language instructions and examples are entirely in Chinese, which can imply a fixed language expectation. Under the policy rule, forcing a specific language without opt-in can be a locale/language policy concern unless the skill explicitly offers a choice or documents a justified region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

A language or locale policy issue can arise when a skill appears to force a specific language without user choice. This reference uses only Chinese throughout and does not mention that the skill is China/Chinese-specific or offer an alternative language option.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.