特色民宿推荐

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed travel-search helper that sends homestay queries to a cloud proxy, with no evidence of hidden persistence, local data access, or destructive behavior.

Install only if you are comfortable sending homestay search details, including destinations, dates, price limits, and preferences, to the skill publisher's cloud proxy for Fliggy lookup. Avoid entering unusually sensitive itinerary details, and the publisher should rotate or better protect the embedded proxy token.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The script hardcodes a proxy access token directly in source code, which creates a secret-exposure risk if the skill is shared, logged, or inspected by unauthorized parties. Anyone who obtains the code can reuse the token to access the external proxy, potentially consuming quota, abusing the backend, or impersonating this skill's traffic.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill forwards user-provided travel queries, which may include destinations, dates, preferences, and other potentially sensitive itinerary information, to an external proxy service without any visible user disclosure or consent flow in the code. This creates a privacy and data-handling risk because users may not realize their inputs are being transmitted to a third-party endpoint outside the local skill environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal