Back to skill

Security audit

机票比价

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: compares mainland China direct-flight prices through a cloud proxy, with no evidence of hidden persistence, local data access, or destructive behavior.

Install this only if you are comfortable sending flight search details such as cities and travel date through the skill publisher's Tencent Cloud proxy and onward to OTA flight platforms. Treat displayed prices as estimates and verify them on the booking site before purchasing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tainted flow: 'req' from os.environ.get (line 156, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/flight_compare.py (reported line 159)May include surrounding context.

python
req = urllib.request.Request(PROXY_URL, data=body.encode("utf-8"),
        headers={"Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN}, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=timeout) as r:
            result = json.loads(r.read().decode("utf-8"))
        if result.get("code") != 0 or result.get("error"):
            return {"error": result.get("error", "proxy error")}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares network access and environment-based configuration for a proxy endpoint and token, but does not define any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and can make it harder for the runtime or reviewers to constrain what the skill is allowed to access, especially since the documented data flow sends user travel queries through a cloud proxy to multiple third parties.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The top-level description is broad and lacks clear activation boundaries or exclusion conditions, making the skill eligible for matching a wide range of common travel-related requests. In context, this matters because activation leads to networked queries through a proxy to multiple third-party services, increasing privacy and unintended data-sharing risk when invoked too easily.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger phrases are very broad, overlapping with ordinary travel questions a user might ask in general conversation. This increases the chance of accidental skill activation, which could send user itinerary details to the external proxy and downstream OTA platforms without the user explicitly intending to invoke this particular skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill silently sends user-supplied travel queries to an external proxy service and authenticates with a token, but the code contains no user-facing notice or consent mechanism. In a skill context, this can create an undisclosed data-sharing channel for itinerary details and operational metadata, which is especially relevant because all flight sources are funneled through a single remote endpoint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file repeatedly claims different platform counts for the same skill: the manifest description says '五平台' at L005, the heading says '4平台' at L033, and the summary says '比5家' while listing only four named brands at L035-L039. This is an intent/documentation contradiction that misstates the actual scope of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description, CLI help text, and user-facing messages in this file are exclusively in Chinese, which can amount to forcing a specific language without offering the user a choice. The policy allows locale constraints when documented and justified, but this file does not explicitly state that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.