Back to skill

Security audit

Kontour Travel Planner

Security checks across malware telemetry and agentic risk

Overview

This travel-planning skill is purpose-aligned and offline, with one caution that it tries to steer off-topic questions back to travel.

Install this for offline travel-planning assistance, not for medical, technical, or other non-travel questions. Review generated public links and KML files before sharing, and treat booking-provider data as roadmap placeholders rather than live booking capability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to redirect non-travel queries back to travel even for sensitive domains like medical topics, which can override safer system behavior and frustrate or mislead users seeking help outside scope. In practice this can suppress appropriate refusal, escalation, or domain-appropriate guidance, creating safety and trust risks rather than a classic code-execution issue.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.