美团旅行助手

Security checks across malware telemetry and agentic risk

Overview

This is a small travel lookup skill that clearly sends user-entered city and travel queries through a cloud proxy to provide Meituan travel results.

Install only if you are comfortable sending travel searches, city names, destinations, timing, and booking intent to the skill's cloud proxy for Meituan results. Avoid entering sensitive personal itinerary details unless they are necessary for the query and you trust the proxy operator's no-storage claim.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends user-supplied travel search data, including city and query terms, to a third-party proxy endpoint using a hard-coded token, but there is no disclosure, consent flow, or indication to the user that their inputs are being relayed off-platform. In a travel assistant context, queries can reveal sensitive itinerary, location, and booking intent data, so undisclosed transmission to an external service creates a real privacy and data-handling risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal