Back to skill

Security audit

find-hotel

Security checks for vulnerabilities and agentic risk

Overview

This hotel-search skill appears purpose-built for RollingGo, but it asks agents to repeatedly run mutable latest-version packages while handling an API key.

Review before installing. Prefer a pinned, reviewed RollingGo CLI version instead of @latest or --refresh, avoid global installs where possible, pass only a dedicated RollingGo_API_KEY to the process, and do not put real API keys directly on command lines. Treat this as a hotel-search integration that contacts RollingGo with your itinerary details, not as a local-only tool.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:57
Finding

Automatic Execution of Unpinned Latest-Version Packages

Content
View full analysis
" ``` The Python execution reference similarly prescribes: ```bash uvx --refresh --from rollinggo@latest rollinggo --help uvx --refresh --from rollinggo@latest rollinggo search-hotels \ --origin-query "Find hotels near Tokyo Disneyland" \ --place "Tokyo Disneyland" --place-type "" ``` ### Technical Analysis The skill explicitly requires executing the current `latest` release from npm or PyPI. No exact version, integrity hash, lockfile, trusted artifact digest, or reviewed package snapshot is provided. The `npx --yes` option suppresses interactive package-installation confirmation. The `uvx --refresh` option deliberately refreshes the package cache, allowing a newly published package to replace the version previously reviewed or executed. The global installation alternatives also modify the user's persistent executable environment. Because the project contains only documentation and no source code for the downloaded `rollinggo` package, the audit cannot verify what the fetched package executes, which network destinations it contacts, or how it handles inherited environment variables. This does not prove that the current package is malicious, but it creates an unsafe mutable-code exec ...[truncated 1597 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/claw-host-env.md:20
Finding

Plaintext and Over-Broad Host Credential Injection Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Using the bare brand term rollinggo as a trigger phrase is overly broad and may invoke the skill when the user is merely mentioning the brand, rather than explicitly consenting to hotel lookup. In this context, mis-triggering is more concerning because the skill can access an API key and send user travel queries to an external service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The pre-flight section tells the agent to check for ROLLINGGO_API_KEY, while the metadata declares RollingGo_API_KEY. This inconsistency can cause the guardrail to fail open or fail closed depending on the host environment's case sensitivity and conventions, leading to accidental command execution failures or misuse of the wrong credential variable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill asks for an API key but does not clearly disclose that commands will use that credential to query an external service and transmit user-supplied hotel search data. This weakens informed consent and can cause users to unknowingly expose travel plans, locations, dates, and preferences to a third party.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states a lookup order involving RollingGo_API_KEY, while earlier instructions require ROLLINGGO_API_KEY. Conflicting credential guidance is dangerous in an agent skill because it undermines deterministic security behavior and can lead operators to set secrets incorrectly, bypass checks, or expose secrets during troubleshooting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs use of rollinggo@latest, which is effectively an unpinned remote package execution path. That allows upstream package changes or a compromised publisher account to alter code executed at runtime, creating a supply-chain risk with access to the user's environment and API key.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The uvx --refresh --from rollinggo@latest guidance fetches and executes the newest package version on every run. In a skill that also depends on an API key, this increases the blast radius of a malicious or compromised upstream release because fresh code is repeatedly trusted and executed automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill file is written in Chinese and does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, a fixed language/locale without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The documentation instructs users to execute npx --yes --package rollinggo@latest ..., which fetches and runs the latest package version at execution time rather than a reviewed, immutable version. In an agent skill context, this creates a supply-chain execution risk: a compromised maintainer account, malicious release, or dependency hijack could lead to arbitrary code execution on the host whenever the skill is used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This line again recommends running rollinggo@latest through npx, causing unreviewed code to be downloaded and executed on demand. Because this skill is specifically designed to trigger hotel-search operations, the unsafe pattern is likely to be exercised frequently, increasing exposure to package compromise or malicious updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
73% confidence
Finding

Although the static match appears imprecise, the surrounding section explicitly states a default rule of always using the npm latest published version. That still promotes execution of mutable third-party code, which is a real supply-chain risk even if the exact matched tokenization is noisy.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This line reiterates the 'latest version by default' command prefix, meaning every invocation can execute different code over time without review. In a tool/skill environment, that undermines reproducibility and turns normal hotel lookup actions into a recurring remote code execution trust decision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document explicitly shows passing the API key via --api-key YOUR_API_KEY without warning that command-line arguments may be exposed via shell history, process listings, terminal logging, CI logs, or agent telemetry. In a hosted agent context, this is more dangerous because execution environments often capture command invocations for debugging or auditing, potentially leaking live credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The troubleshooting guidance again instructs falling back to npx --yes --package rollinggo@latest ..., preserving the same mutable-package execution risk under error conditions. This is particularly dangerous because users are likely to follow troubleshooting steps quickly and with less scrutiny, making exploitation through a malicious update more plausible.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The document instructs users to execute uvx --refresh --from rollinggo@latest, which always resolves and runs the newest published package rather than a reviewed, immutable version. This creates a supply-chain risk: if the package is compromised, typosquatted, or a malicious update is published, the host may immediately execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example again uses uvx --refresh --from rollinggo@latest, causing code execution from the latest upstream release at runtime. In an agent skill context, such instructions are especially risky because automation may run them non-interactively, turning any upstream compromise into immediate remote code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The 'version freshness' section explicitly mandates using the latest published version on every execution. That amplifies supply-chain exposure by disabling stability and review, and ensures any malicious or breaking upstream release is pulled into execution immediately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation recommends passing --api-key YOUR_API_KEY on the command line without warning that command-line arguments may be exposed via shell history, process listings, logs, or telemetry. This can leak credentials to other local users, monitoring systems, or support artifacts and enable unauthorized API access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The hotel-tags example includes transient execution from the latest package release, which means even a read-only seeming command can trigger installation and execution of untrusted updated code. Because this skill is designed for hotel search operations, there is no strong business need to accept dynamic code changes at every invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The troubleshooting advice recommends uvx --refresh --from rollinggo@latest, normalizing insecure package execution during error recovery. This is dangerous because users are more likely to follow copy-paste fixes under troubleshooting pressure, increasing the chance of running a compromised upstream release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

uvx --refresh --from . rollinggo --help executes code from the local working directory, which can be unsafe if the repository contents are untrusted or have been tampered with. In local development sections this is less severe than pulling @latest, but it still creates a code-execution risk when copied into untrusted environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

该技能的自然语言说明、用户提示和操作指引均固定为中文,未看到提供多语言选项、按用户语言响应的说明,或对中文限定给出明确业务理由。根据语言/locale 政策,这可能构成未获用户选择的语言约束。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.