Back to skill

Security audit

Airbnb Agent

Security checks for vulnerabilities and agentic risk

Overview

This Airbnb search skill is purpose-aligned and disclosed, with ordinary setup, network, and local-output risks users should understand before use.

Install only if you are comfortable with the skill creating a local Python virtual environment, installing current pip versions of pyairbnb and curl-cffi, sending your search parameters to Airbnb, and writing listing results under /tmp unless you choose another output path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:14
Finding

Unpinned Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh, line 14
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
"$VENV/bin/pip" install --quiet pyairbnb curl-cffi

Technical Analysis

The setup script installs pyairbnb and curl-cffi without exact version constraints, a lock file, or package hash verification. Consequently, each fresh installation resolves whatever package versions and transitive dependencies are available from the configured Python package index at that time.

This does not establish that either dependency is currently malicious. However, it creates a supply-chain exposure because the installed code may differ from the code reviewed or tested by the project author. A compromised package release, compromised maintainer account, unsafe package-index configuration, or malicious transitive dependency could introduce attacker-controlled code. Python packages may execute code during installation, and imported packages execute code within the application process at runtime.

Attack Path

  1. An attacker compromises a dependency, one of its transitive dependencies, its maintainer account, or the package distribution channel.
  2. The attacker publishes a malicious version that still satisfies the unconstrained package names.
  3. A user performs a fresh setup by running bash scripts/setup.sh.
  4. pip resolves and installs the malicious or compromised release because no approved versions or hashes are enforced.
  5. Malicious code executes during package installation or when search.py imports pyairbnb or details.py imports curl_cffi.
  6. The code operates with the privileges of the user running the setup or application.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the installing or executing user. Depending on those privileges and the host environment, the attacker could read or modify user-accessible ...[truncated 365 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin all direct and transitive dependencies to reviewed versions in a lock file.
  2. Generate and verify cryptographic hashes for every package artifact.
  3. Install dependencies using hash enforcement, for example:
bash
"$VENV/bin/pip" install --require-hashes -r requirements.txt
  1. Maintain a requirements.txt or equivalent lock file containing exact versions and hashes, such as:
text
pyairbnb==REVIEWED_VERSION --hash=sha256:REVIEWED_HASH
curl-cffi==REVIEWED_VERSION --hash=sha256:REVIEWED_HASH
  1. Include all transitive dependencies in the lock file rather than allowing them to resolve dynamically.
  2. Review dependency changes and security advisories before deliberately updating the lock file.
  3. Use a trusted package index explicitly and protect build environments from user-controlled pip configuration or index overrides.
  4. Consider installing from pre-vetted artifacts in a controlled internal repository for higher-assurance deployments.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared behavior promises detail-page analysis for parking, basement, and renovation signals, but the finding indicates those capabilities are not actually implemented. This mismatch is dangerous because downstream users or agents may trust the skill's output for screening or decision-making, leading to false assurances, missed risks, or inappropriate automation based on nonexistent analysis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises executable setup and Python scripts that imply shell, network, and file-write capabilities, but it declares no explicit tool scope or permissions boundary. In an agent environment, this can cause the skill to be run with broader privileges than users or orchestrators expect, increasing the risk of unintended command execution, outbound requests, or writes to sensitive paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTTP headers hard-code "Accept-Language": "en-US,en;q=0.9", which imposes a specific language/locale preference. This is a natural-language policy concern because the skill does not offer user opt-in or explain why this locale restriction is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command-line argument for language is hard-coded to default to "zh", which forces a specific locale unless the user explicitly overrides it. This is a natural-language policy concern because the skill imposes a language choice by default rather than offering a neutral default or explicit opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file documents that the skill writes candidate and result data to /tmp/airbnb_candidates.json and /tmp/airbnb_results.json, but it does not explicitly warn users that local files will be created and may overwrite prior outputs or persist on the system. Because this is user-affecting file output behavior in the skill description, a brief disclosure would improve safety and transparency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes user-facing example content in Chinese (for example, the title value) while presenting itself as a general API fields reference. Because the document does not state that the skill is China-locale specific or give users a language/locale option, it may violate the language/locale policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The price breakdown examples and the instruction to find the item with "折后" in the description rely on Chinese-language content as if it were universally applicable. In a general reference file, hard-coding a specific language expectation without documenting the locale scope can create a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.