Back to skill

Security audit

AI机票预订助手

Security checks for vulnerabilities and agentic risk

Overview

This flight-booking skill matches its stated purpose, but it handles payments, refunds, credentials, and identity data with several unsafe implementation choices users should review before installing.

Review this skill before installing. It should only be used for the intended Fenbeitong/Chinese flight workflow, and preferably only after fixing TLS verification, locking API traffic to an approved endpoint, storing credentials in a user-private secret store, redacting passenger identity data from output, and requiring explicit confirmations before booking, cancellation, change, or refund actions. Avoid using it on shared machines or in environments where inherited environment variables may be untrusted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.py:159
Finding

TLS Certificate Verification Is Disabled for Sensitive API Traffic

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.py:15
Finding

Runtime API Destination Override Can Redirect Credentials and PII

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.py:20
Finding

API Key and Phone Number Are Stored in an Unsafe Shared Temporary File

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search_price.py:24
Finding

Predictable Temporary Seat-State Files Permit Transaction Tampering

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_order.py:100
Finding

Scripts Print Full Passenger PII and Raw Transaction Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth.py:90
Finding

Verification Codes and Passenger Identity Data Are Passed as Command-Line Arguments

Content
View full analysis
") sys.exit(1) phone = sys.argv[2] send_verification_code(phone) elif action == "verify": if len(sys.argv) != 4: print("用法: python3 auth.py verify ") sys.exit(1) phone = sys.argv[2] code = sys.argv[3] verify_and_get_api_key(phone, code) ``` The booking script similarly receives all passenger PII through process arguments: ```python if len(sys.argv) != 5: print("用法: python3 create_order.py ") print("示例: python3 create_order.py 1 \"张三\" \"13800138000\" \"110101199001011234\"") sys.exit(1) seat_index = sys.argv[1] passenger_name = sys.argv[2] passenger_phone = sys.argv[3] passenger_id = sys.argv[4] ``` ### Technical Analysis Command-line arguments may be visible in process listings and process metadata while the command runs. If invoked through a shell or orchestration layer, they may also be stored in shell history, Agent tool-call records, job metadata, audit logs, and telemetry. SMS verification codes are short-lived but security-sensitive authentication factors. Identity-document numbers are long-lived PII and cannot be safely rotated after disclosure. ### Attack Path 1. The user or Agent invokes the documented authentication or booking command with sensitive values in its argument list. 2. The operating system exposes the argument vector to authorized local process-inspection tools, or the execution framework records the command. 3. A local observer, administrator, monitoring service, ...[truncated 586 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description focuses on flight assistance, but the documented behavior also includes SMS verification, apiKey issuance, persistence to ~/.fbt_auth.json, and auth-state reuse across sessions. This mismatch can mislead users and integrators about data flows, credential handling, and account linkage, especially because phone numbers and auth tokens are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description focuses on flight assistance, but the documented behavior also includes SMS verification, apiKey issuance, persistence to ~/.fbt_auth.json, and auth-state reuse across sessions. This mismatch can mislead users and integrators about data flows, credential handling, and account linkage, especially because phone numbers and auth tokens are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description focuses on flight assistance, but the documented behavior also includes SMS verification, apiKey issuance, persistence to ~/.fbt_auth.json, and auth-state reuse across sessions. This mismatch can mislead users and integrators about data flows, credential handling, and account linkage, especially because phone numbers and auth tokens are involved.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase '退票' is too broad for a destructive, financially significant operation. Even though the document later mentions confirmation, such a broad activation phrase raises the risk that a casual mention of refunds initiates a sensitive workflow and, combined with contradictory refund instructions elsewhere, could result in unintended refund submission.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code unconditionally creates an unverified SSL context for outbound HTTPS requests, which disables certificate validation and defeats TLS server authentication. In a flight-booking assistant that sends authentication tokens and personal booking data, this enables man-in-the-middle interception or modification of API traffic, making the issue especially dangerous in real-world networks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill performs network access, reads and writes local files, and relies on environment/runtime capabilities, but it does not declare any explicit tool scope or permissions boundary. That makes the skill's operational power opaque to reviewers and increases the chance of over-broad execution or accidental access to sensitive local state such as auth files and temporary booking data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Using a broad trigger like '预订' can cause the skill to activate in ambiguous conversations and move users into a booking workflow prematurely. In a system that may later collect identity data and create orders, accidental invocation increases the risk of unintended data collection or transactional actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The full-flow examples use command signatures that differ from the earlier interface definitions, including extra phone parameters in later order, cancel, endorse, and refund calls. Inconsistent invocation guidance can lead implementers or agents to pass the wrong arguments, mishandle user PII, or call the wrong action path in a transactional workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document contains conflicting instructions for refunds: one section requires an explicit second confirmation, while the example says the system will automatically submit after confirmation of the fee display. In a refund workflow, contradictory instructions can cause unauthorized or premature irreversible actions, especially because '退票' is financially sensitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module description and all user-facing messages are written exclusively in Chinese, indicating the skill expects or forces a specific language experience. There is no visible opt-in, language selection, or justification that this is a region-specific tool, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code includes multiple user-facing strings in Chinese, such as the usage text, progress messages, and success/failure output. The file does not provide any user opt-in, language selection, or documentation indicating that the skill is intentionally limited to Chinese-speaking users, which creates a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill persists the apiKey and phone number in a predictable temp-directory file, which may be readable by other local users, captured by system cleanup tools, or left behind longer than expected. Storing credentials in temporary storage is risky because temp locations are not designed as secure secret stores and the code does not set restrictive permissions or encryption.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline comment acknowledges that certificate verification should be enabled in production, but the implementation still disables it unconditionally. This mismatch is dangerous because it can mislead reviewers or operators into believing transport security is intact when it is not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The API wrapper sends the apiKey and arbitrary extra parameters such as name, phone, and idCard to a remote endpoint via HTTP POST. While the function docstring describes parameters, it does not provide a user-facing warning that sensitive personal and authentication data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The authenticated request path repeats the same documented-but-disabled certificate validation pattern, exposing apiKey and passenger-related data during the most sensitive operations. Because this path carries credentials and booking information, the contradiction hides a materially unsafe transport configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends highly sensitive personal data including passenger name, phone number, and national ID number to an API without any explicit consent prompt, privacy notice, masking, or confirmation step. In a flight-booking context this data transfer may be operationally necessary, but failing to warn users or confirm transmission increases privacy and compliance risk if the user did not intend to submit real PII or if logs/output expose the data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script prints the full order_data object to stdout immediately before calling the endorse API. That object contains sensitive identifiers including order_id, ticket_ids, and seat/segment details, which can be exposed through terminal history, logs, orchestration platforms, or monitoring systems. In a flight booking/change skill, these values are operationally sensitive and could enable unauthorized order lookups, social engineering, or privacy leakage if logs are accessible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file uses Chinese-only docstrings, usage text, status messages, and error output throughout the script. That creates a language-policy concern because the skill effectively forces a specific language without offering the user any locale choice or documenting that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file uses Chinese-only docstrings, comments, CLI usage text, and runtime output throughout, which imposes a specific language on users. Under the policy, locale or language constraints should either be optional for the user or clearly documented as justified for a region-specific tool, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script submits a refund request immediately after gathering product IDs, with no confirmation prompt, review screen, or secondary verification before triggering a potentially irreversible financial action. In a flight booking/refund skill, accidental invocation, argument tampering, or misuse by an upstream agent could cause unintended ticket refunds, customer disruption, and monetary loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains multiple user-facing strings, including docstrings, usage text, status messages, and table headers, all in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all subsequent user-facing strings indicate the skill is designed to operate only in Chinese. Under the policy, forcing a specific language without user opt-in or a clearly documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description advertises a wide range of high-impact actions such as flight search, booking, rescheduling, and refunds without defining clear trigger boundaries, confirmation requirements, or exclusions. In a travel/transaction skill, overly broad activation language can cause the agent to invoke the skill in ambiguous contexts and potentially initiate sensitive booking or account-affecting workflows when the user did not intend it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description is entirely in Chinese and implies Chinese-language operation without stating whether this is a locale-specific skill or whether users can choose another language. This can create misrouting or misunderstanding during sensitive travel transactions, where incorrect interpretation of dates, names, fare rules, or consent could lead to booking errors or unintended modifications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The module description and user-visible strings are written only in Chinese, with no indication that another language can be selected. This may violate language/locale policy if the skill is expected to support user choice rather than forcing a single language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.