T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:138- Finding
Booking Cancellation Does Not Enforce Ownership or Administrator Authorization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent studio-booking guide, but its booking cancellation and payment examples under-specify authorization and privacy controls for sensitive customer and payment workflows.
Review this skill carefully before installation or use. It is not showing hidden execution or malicious behavior, but do not treat the code snippets as production-ready: add authenticated user context, owner/admin checks for booking cancellation and payment generation, strict callback validation, refund authorization, audit logging, and privacy controls for phone numbers, booking history, and payment metadata.
SKILL.md:138Booking Cancellation Does Not Enforce Ownership or Administrator Authorization
SKILL.md:250Telegram Payment Callback Uses an Untrusted Booking Reference Without a Documented Authorization Check
SKILL.md:90Customer Phone Number and Payment Metadata Are Embedded in a URL Query String
Suspicious Unicode normalization or mixed-script content
The entire skill is written as Russian-only operational guidance, with no indication that language selection is optional or that the skill is intentionally restricted to Russian-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill instructs the agent to collect contact details, booking status, visit history, and customer statistics, but it provides no privacy notice, retention limits, access-control guidance, or minimization requirements. In a booking context this can lead to unnecessary collection and exposure of personal data, increasing regulatory and confidentiality risk if logs, chat history, or backend records are accessed improperly.
No suspicious patterns detected.