Back to skill

Security audit

travel-world

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Travel World MCP connector for travel search and planning, with no hidden code or destructive behavior found.

Install only if you are comfortable sending travel searches and trip details to Travel World's hosted MCP server using your API key. Treat it as a live travel-search connector, not a general travel-advice skill, and confirm before sharing sensitive itinerary details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description uses broad activation phrasing such as planning trips and discovering options, which can cause the agent to invoke this third-party integration for loosely related travel conversations without clear user intent. In practice, that increases the chance of unnecessary data sharing to the hosted MCP server and tool overuse beyond the user's expectations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The 'When to use this skill' section gives only positive triggers and lacks boundaries for when not to call the external service. That ambiguity can lead an agent to send itinerary details, destinations, or timing information to the provider during normal conversation rather than only after a clear request for travel search or status lookup.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explains how to connect to a hosted MCP server but does not warn that user travel queries, itinerary details, and possibly other personal trip information will be transmitted to a third-party service. Because travel data can reveal locations, dates, companions, and preferences, the missing disclosure undermines informed consent and increases privacy risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.