Back to skill

Security audit

Road Trip Planner

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed road-trip and map-planning helper, with only minor scope and disclosure issues around broad triggers and external live-data checks.

Install if you are comfortable with a travel-planning skill using Amap and other official live-information sources. Avoid sharing unnecessary sensitive location details, and review outputs involving live road, weather, or attraction status before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Low
Confidence
81% confidence
Finding
The manifest frames this skill as an Amap-based road-trip route planner that generates personal map QR codes and itinerary details. Lines L316-L325 add a broader real-time verification capability using official traffic, weather, and attraction-status sources, which is not justified by the declared dependency set and goes beyond the stated Amap/personal-map planning scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill when users mention general phrases like route planning, travel itineraries, map generation, or mileage queries. These intents are broader than road-trip-specific activation and could overlap with ordinary travel or mapping conversations, increasing the chance of accidental invocation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The listed intents mix specific road-trip scenarios with generic requests like personal map generation and mileage queries, but do not define when the skill should not activate. Without negative examples or scope boundaries, the activation criteria remain ambiguous for adjacent use cases.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.