Back to skill

Security audit

Travel Planning Cellcog

Security checks across malware telemetry and agentic risk

Overview

This travel-planning skill is a coherent CellCog integration, but users should understand that travel prompts and details are sent to CellCog for processing.

Install only if you are comfortable using CellCog as an external travel-planning provider. Avoid including unnecessary sensitive details such as passport numbers, exact home addresses, confidential business schedules, or regulated personal data unless you have reviewed CellCog's privacy and retention practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages users to submit highly specific travel details such as dates, destinations, budgets, family composition, and business travel plans to a third-party CellCog service, but the description does not disclose that this information will be transmitted externally. This creates a privacy and operational security risk because users may unknowingly share sensitive itinerary data that could expose personal habits, absence from home, or corporate travel plans.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.