Back to skill

Security audit

DeepTrip

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed travel-assistant skill that sends travel questions to Tongcheng/DeepTrip and offers booking links, with privacy cautions around login prompts and shared trip context.

Install only if you are comfortable sending travel questions, dates, budgets, destinations, and related preferences to Tongcheng/DeepTrip. Do not sign in through the WeChat/Tongcheng link unless you need booking or account continuity, and share only the minimum trip context needed for recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill mandates proactively sending users to a third-party login URL and encouraging account sign-in, but it does not clearly disclose what data will be collected, how authentication will be used, or the privacy implications of linking an account. This can pressure users into authenticating before they understand the consequences, increasing the risk of unnecessary credential sharing and privacy loss.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation instructs callers to send user queries directly to a remote API endpoint without warning that the content of those queries leaves the local environment and is processed by an external travel service. Users may unknowingly transmit sensitive travel plans, personal preferences, or identifiers to a third party.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill explicitly tells integrators to enrich outbound queries with prior conversation context, including user constraints and prior recommendations, without warning that this additional context may contain personal or sensitive information. This increases the amount of user data disclosed to the external API beyond what may be strictly necessary.

Ssd 3

Medium
Confidence
98% confidence
Finding
The guidance encourages forwarding prior user dialogue details to the external travel provider so the provider can resolve follow-up queries. In a travel context, historical dialogue can contain budgets, destinations, dates, companions, and other sensitive details, creating unnecessary third-party disclosure risk if sent wholesale.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.