Back to skill

Security audit

Renfe

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Renfe booking purpose, but it warrants review because it can auto-download and run a GitHub release binary while storing passenger identity and payment-adjacent details locally.

Install only if you are comfortable with a third-party Renfe CLI handling train purchases, storing passenger identity/contact data locally, and downloading its executable from the publisher's GitHub release if the CLI is not already installed. Prefer installing the pinned Go module yourself from a trusted environment, review or delete ~/.config/renfe/passengers.json when no longer needed, and confirm every fare and Bizum payment request before approving it in your bank app.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill invokes shell commands, launches a browser, accesses the network, and reads/writes files, but it does not declare any explicit tool scope such as allowed tools or permissions. That omission can cause an agent runtime to grant overly broad default capabilities or make unsafe assumptions about what the skill is permitted to do, increasing the blast radius if the skill is misused or compromised.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill instructs the agent to collect and persist highly sensitive personal and payment-adjacent data in ~/.config/renfe/passengers.json, including full name, identity document, email, phone number, and Bizum phone. Even with mode 600, storing this data long-term on disk creates privacy and retention risk, especially in shared, multi-tenant, or loosely sandboxed agent environments.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Setup

  • Supported on macOS and Linux. The CLI needs network access to renfe.com. Booking also starts a Chromium-based browser (Helium, Chrome or Chromium; RENFE_BROWSER overrides it) and writes to ~/.config/renfe/. In a sandboxed agent, request those permissions for book, pay and ticket.
  • Booking reads travellers from ~/.config/renfe/passengers.json. If it is missing, ask the user for each traveller's details and write the file in this format, with permissions 600. Never invent personal details.
    json
    {"bizum_phone": "+34600000000", "passengers": [{"id": "me", "type": "adult", "name": "...", "surname1": "...", "surname2": "...", "document_type": "DNI", "document": "...", "email": "...", "phone": "+34600000000"}]}
    

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
## Rules

- Buy only when the user asked to book or buy. Searching and `--dry-run` need no approval.
- Never raise `--max-total` above the user's budget or the quoted total without asking.
- Pay at most once per trip. After `payment_pending`, a timeout, or any error once `pay` started, do not run `book` or `pay` again for that trip. Ask the user whether they approved the Bizum request and check for Renfe's email first.
- Run one `book`/`pay` at a time; they share one browser and fail if another is running.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
## Rules

- Buy only when the user asked to book or buy. Searching and `--dry-run` need no approval.
- Never raise `--max-total` above the user's budget or the quoted total without asking.
- Pay at most once per trip. After `payment_pending`, a timeout, or any error once `pay` started, do not run `book` or `pay` again for that trip. Ask the user whether they approved the Bizum request and check for Renfe's email first.
- Run one `book`/`pay` at a time; they share one browser and fail if another is running.
- Report the `locator` from a confirmed booking and give the user `ticket_pdf`. A `ticket_error` means only the PDF failed; the purchase stands. Fix it with `renfe ticket LOCATOR`, never by paying again.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/renfe (reported line 23)May include surrounding context.

text
# the skill folder, which installers checksum to detect local changes.
	mkdir -p "$cache"
	cp "$skill_dir/bin/renfe" "$cache/renfe.bundled"
	chmod 755 "$cache/renfe.bundled"
	exec "$cache/renfe.bundled" "$@"
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/renfe (reported line 70)May include surrounding context.

text
# the skill folder, which installers checksum to detect local changes.
	mkdir -p "$cache"
	cp "$skill_dir/bin/renfe" "$cache/renfe.bundled"
	chmod 755 "$cache/renfe.bundled"
	exec "$cache/renfe.bundled" "$@"
fi

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The wrapper will download and execute a release binary from GitHub at runtime if no suitable local binary is present. Although it verifies a SHA-256 checksum, the checksum file is fetched from the same remote source as the binary, so a compromised GitHub release or repository can still deliver a malicious payload that will be executed on the user's machine.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.