Back to skill

Security audit

Studio Booking Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent studio-booking guide, but its booking cancellation and payment examples under-specify authorization and privacy controls for sensitive customer and payment workflows.

Review this skill carefully before installation or use. It is not showing hidden execution or malicious behavior, but do not treat the code snippets as production-ready: add authenticated user context, owner/admin checks for booking cancellation and payment generation, strict callback validation, refund authorization, audit logging, and privacy controls for phone numbers, booking history, and payment metadata.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:138
Finding

Booking Cancellation Does Not Enforce Ownership or Administrator Authorization

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:250
Finding

Telegram Payment Callback Uses an Untrusted Booking Reference Without a Documented Authorization Check

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:90
Finding

Customer Phone Number and Payment Metadata Are Embedded in a URL Query String

Content
View full analysis
str: payload = { "amount": str(amount), "order_id": order_id, "description": description, "shop_id": shop_id, "callback_url": callback_url, "expires_in": str(expires_in), } if user_phone: payload["phone"] = user_phone sign_str = json.dumps(payload, separators=(",", ":"), sort_keys=True) signature = hmac.new( secret_key.encode(), sign_str.encode(), hashlib.sha256 ).hexdigest() payload["signature"] = signature return f"https://telegapay.com/pay?{urlencode(payload)}" ``` ### Technical Analysis The function includes the customer's phone number in the payment URL query string. It also places the order ID, description, shop ID, callback URL, expiration value, and HMAC signature in the URL. URL encoding changes the representation of the data but does not provide confidentiality. Query strings are routinely captured by browser history, Telegram clients, reverse proxies, web-server access logs, analytics platforms, monitoring systems, screenshots, support records, and URL-sharing workflows. Depending on referrer policy and redirect behavior, query data may also be propagated to other services. The HMAC protects payload integrity but does not encrypt the payload. Anyone who obtains the URL can read its contents and may be able to reuse the complete signed URL until it expires. ### Attack Path 1. A payment link is generated with `user_phone` populated. 2. The function serializes the phone number and payment metadata into the URL query string. 3. The link is s ...[truncated 941 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill is written as Russian-only operational guidance, with no indication that language selection is optional or that the skill is intentionally restricted to Russian-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to collect contact details, booking status, visit history, and customer statistics, but it provides no privacy notice, retention limits, access-control guidance, or minimization requirements. In a booking context this can lead to unnecessary collection and exposure of personal data, increasing regulatory and confidentiality risk if logs, chat history, or backend records are accessed improperly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.