Back to skill

Security audit

汽车票查询与预订

Security checks for vulnerabilities and agentic risk

Overview

This skill is a purpose-aligned travel lookup tool, but users should be aware it sends travel and lodging queries to external proxy/map services.

Install only if you are comfortable sending travel routes, station locations, and hotel preferences to the skill's external proxy and map services. Do not set PROXY_TOKEN in the environment unless it is intended for this proxy integration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tainted flow: 'req' from os.environ.get (line 32, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/bus_ticket.py (reported line 39)May include surrounding context.

python
)
    _timeout = timeout or TIMEOUT
    try:
        with urllib.request.urlopen(req, timeout=_timeout) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        err = ""

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

整体上,代码的目标与描述高度一致:汽车票查询、去汽车站交通查询、住宿推荐三项能力都与声明相符,且使用同程和高德代理接口也符合“多旅游平台数据直连”的表述。不过仍存在两处较明显的不一致。首先,住宿推荐功能在实现上有实质性缺陷:recommend_hotel 调用 _call_tc(..., timeout=60),但 _call_tc 只接受 (rtype, params) 两个参数,因此该功能会因参数不匹配而失败,意味着声明的住宿推荐能力并未被代码正确实现。其次,search_bus 虽然对日期进行了复杂解析和提示,但实际请求参数只包含 departure 和 destination,没有把 dep_date/parsed_date 传入远程搜索接口,因此“按指定日期查询班次”的实现与声明/输出文案不完全匹配。基于评估标准,这属于描述与实际行为存在材料性偏差,因此应判定为 mismatch。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares external data access through cloud proxy and map providers but does not define any explicit tool scope, permissions, or allowed-tools boundaries. Missing scope restrictions increases the risk of unintended network or environment access if the runtime grants broader capabilities than the manifest communicates, making review and containment harder.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/bus_ticket.py (reported line 30)May include surrounding context.

python
# ============ 代理调用 ============
def _call_proxy(url, rtype, params, timeout=None):
    body = json.dumps({"type": rtype, "params": params}, ensure_ascii=False, separators=(",", ":")).encode("utf-8")
    req = urllib.request.Request(
        url, data=body,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user-provided travel queries, origins/destinations, station names, and hotel preference text to third-party proxy endpoints without any visible disclosure, consent flow, or minimization in this file. Travel itineraries and lodging preferences can reveal sensitive behavioral and location information, so silent transmission to external services creates a privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest fields, examples, and usage instructions are entirely in Chinese, which effectively forces a specific language experience. The file does not indicate that language selection is optional or that the skill is limited to a Chinese-speaking audience by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module description and all user-facing strings are exclusively in Chinese, which effectively forces a specific language for interaction. Under the policy, language constraints should be optional, user-selectable, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

L348 的 docstring 明确描述为“AI智能匹配高分酒店”,但 L352 仅调用外部 tongcheng_travel_search 代理并未在本地实现任何 AI 匹配或评分逻辑。这里不是简单的信息缺失,而是文档对实现方式和能力作了更强表述,容易让使用者误解技能的实际行为。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.