Back to skill

Security audit

travel planner

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly travel-related, but it asks for broad browser, shell, authenticated-session, and recurring-task behavior without enough safeguards.

Review before installing. Use a dedicated browser profile or low-privilege accounts, avoid enabling the documented price-monitor cron task unless it has an expiry and cancellation path, and prefer the Python weather script or encoded HTTP calls instead of shell curl. Treat scraped Xiaohongshu content and links as untrusted and confirm before any authenticated browsing or booking-related action.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:77
Finding

Shell Command Injection Through Unvalidated City Input

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
references/examples.md:199
Finding

Persistent Recurring Task Created Without Lifecycle Safeguards

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/prompts.md:9
Finding

Indirect Prompt Injection Through Untrusted Social-Media Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an end-to-end travel research and booking assistant with multiple external data-gathering capabilities. The supplied code chunk is only a report generator. It accepts already-prepared JSON inputs, formats them into a report, computes a simple budget range by adding a flight price, and saves the output. There is no network access, no scraping/searching of Xiaohongshu, no querying of Fliggy, no weather API use, and no evidence of smart caching or parallel execution. While the generated report structure is consistent with travel planning, the code does not implement most of the substantive capabilities claimed in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad end-to-end travel planning skill with multi-source research, flight price querying, booking assistance, and report generation. The supplied code only implements weather forecast retrieval for a destination city using external weather APIs and output formatting. Weather fetching is one small subset of the declared functionality, but the primary purpose of this code chunk is materially narrower than the declared skill behavior. There are no signs of unrelated harmful behavior, but there is a clear description-to-code mismatch because the major advertised capabilities are absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises an end-to-end trip planning skill with multiple integrated capabilities: Xiaohongshu research, flight price lookup on Fliggy, weather retrieval, and final report generation. The provided code chunk is much narrower: it is a single script for Xiaohongshu-related processing only, and even that functionality is mostly unimplemented placeholders marked TODO. The script accepts destination/keyword arguments, calls a stub search function that returns no results, calls a stub extraction function that returns an empty structure, and writes/prints JSON. There is no evidence of Fliggy access, weather APIs, booking assistance, report synthesis, smart caching, or parallel execution. This is therefore a clear description-to-behavior mismatch, primarily because the actual code implements only a partial and largely nonfunctional subset of the declared purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation examples are broad, ordinary travel-planning phrases that closely match normal user conversation, increasing the chance the skill is invoked unintentionally. Because this skill performs automated browsing and may use logged-in travel-platform sessions, unintended invocation could trigger account-backed actions or expose personal session context without the user explicitly opting in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These additional examples further normalize broad natural-language triggers without clear boundaries for when the automation should activate. In the context of a travel-booking assistant that searches third-party sites and may reuse browser sessions, ambiguous triggering raises the risk of unintended data access, unnecessary browsing, or accidental progression toward authenticated workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README mentions browser profile reuse and login persistence but does not adequately warn that automated browsing under an authenticated Fliggy or Xiaohongshu session can expose personal account data, saved traveler information, order history, or other sensitive session-scoped content. This is more dangerous in this skill’s context because travel platforms commonly contain PII and payment-adjacent data, and session reuse increases the chance that automation operates with more privilege than the user expects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents scripts/query_weather.py as an existing component in the current skill structure at L100, which implies weather-query functionality is already part of the skill. However, L186 lists destination weather querying as a future optimization item, contradicting the earlier documentation about current capabilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill document describes use of network access, browser automation, shell execution via curl, and caching, but it does not declare any explicit tool scope or permission boundaries. Missing scope declarations can cause the runtime or reviewer to underestimate the skill’s external access and execution capabilities, reducing user consent and security review effectiveness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not warn users that it will contact third-party weather and travel services, despite explicit instructions to open Xiaohongshu and Fliggy pages and issue a curl request to wttr.in. This creates a transparency and privacy risk because user-supplied itineraries, destinations, and travel dates may be transmitted off-platform without clear disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title, instructions, examples, and output expectations are written to operate in Chinese and target Chinese travel platforms, but there is no opt-in or documented locale constraint. This creates a natural-language policy issue because the skill effectively imposes a language/locale on users without presenting a choice or clearly justifying the restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation examples are broad enough to match ordinary travel-planning requests, which can cause the skill to activate unexpectedly in contexts where the user did not intend third-party lookups or browser automation. Because this skill is designed to make external requests, overbroad triggering increases the chance of silent data disclosure about travel plans, dates, or destinations to outside services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow explicitly relies on persistent logged-in sessions for Xiaohongshu and Fliggy and instructs manual QR-code login, but provides no user-facing warning, consent, or account-scope limitation guidance. That creates a real privacy and account-use risk because the automation may act within a user's authenticated browser context, exposing personal account data, saved preferences, or booking history beyond what is needed for itinerary research.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example documents a cron-based price monitoring workflow that creates ongoing behavior and user notifications, which goes beyond one-shot trip research/report generation described in the skill metadata. Even in documentation, this can normalize deployment of persistent automation without clear scope, consent, retention, or lifecycle controls, leading to surprise background actions and policy drift.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example instructs the skill to set up daily monitoring and notify the user when a threshold is met, but it does not warn that this creates persistent background processing. Users may believe they are making a one-time query when they are actually authorizing continuous checks and outbound notifications, which is a transparency and consent failure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file defines all prompts, field names, examples, and output conventions entirely in Chinese, including explicit output tokens such as "待补充" and Chinese schema labels. Because the skill does not offer a language choice or explain that it is intentionally limited to a Chinese-language/Xiaohongshu-specific context, it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the skill's purpose exclusively in Chinese. This is a natural-language locale policy issue because the file forces one language for user-facing documentation without offering an opt-in or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and argument help text are entirely in Chinese, and the Open-Meteo path explicitly documents city as Chinese-only input. This imposes a language/locale constraint without user opt-in or a documented justification that the tool is region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/query_weather.py (reported line 126)May include surrounding context.

python
try:
        url = (
            f"https://api.open-meteo.com/v1/forecast"
            f"?latitude={coords['lat']}"
            f"&longitude={coords['lon']}"
            f"&daily=weather_code,temperature_2m_max,temperature_2m_min,precipitation_probability_max"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring is entirely in Chinese and presents the skill as Chinese-language only, with no indication that users may choose another language or locale. The policy explicitly flags language/locale constraints when they are imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes an end-to-end travel research component that searches Xiaohongshu and extracts travel insights. In this file, both core functions are stubs marked TODOs: search_xiaohongshu never performs a search and returns an empty list, while extract_travel_info ignores input notes and returns an empty template object.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill extracts Xiaohongshu note content, metadata, image URLs, and outbound links, but omits any warning that it is collecting third-party content and links from an external platform. This is risky because downstream users may unknowingly ingest copyrighted or sensitive third-party material, and outbound URLs can carry tracking parameters or lead to unsafe destinations if surfaced without notice or validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation recommends constructing direct Fliggy search-result URLs containing trip details such as departure city, arrival city, and travel dates in query parameters, but does not warn that these details may be exposed in browser history, logs, referrers, or screenshots. While the data is not highly sensitive by itself, travel itinerary information is still personal and can be leaked through routine telemetry or shared artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

All user-facing examples and guidance are presented in Chinese, and there is no indication that other languages are supported or that Chinese output is optional. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script sends the requested city to wttr.in and also contacts api.open-meteo.com, which shares user-provided query context with third parties. While network access is central to the script's purpose, there is no visible disclosure in CLI output or comments that destination data is sent to external services.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring for search_xiaohongshu says it searches Xiaohongshu and returns a list of dict of guides. However, the function contains only TODO comments, prints status messages, and returns results initialized as an empty list, which contradicts the documented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.