Back to skill

Security audit

酒店比价

Security checks for vulnerabilities and agentic risk

Overview

This hotel comparison skill does what it advertises, but it sends travel search details through publisher-operated cloud proxies and ships a shared proxy token directly in its code.

Review this skill before installing if you are uncomfortable sending hotel searches, dates, locations, and POI preferences through the publisher's cloud proxy. The main issue is not hidden booking or local system access, but the exposed shared proxy token and limited transparency/control around the proxy path.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hotel_compare.py:19
Finding

Hard-Coded Shared Proxy Authentication Token

Content
View full analysis

Vulnerability Details

File Location: scripts/hotel_compare.py, lines 19–20, 37–42, 50–51, and 57–62
Vulnerability Type: Hard-coded authentication credential
Risk Level: High

Vulnerable Code

python
PROXY_URL = "https://1439498936-4wdncmn2oj.ap-guangzhou.tencentscf.com"
PROXY_TOKEN = "tp_8k2mX9vQ4z"
python
req = urllib.request.Request(
    PROXY_URL, data=body,
    headers={"Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN},
    method="POST"
)
python
TOURMIND_PROXY = "https://1439498936-6cmx3jxanz.ap-guangzhou.tencentscf.com"
TOURMIND_TOKEN = "tp_8k2mX9vQ4z"
python
req = urllib.request.Request(
    TOURMIND_PROXY, data=body,
    headers={"Content-Type": "application/json", "X-Proxy-Token": TOURMIND_TOKEN},
    method="POST"
)

Technical Analysis

The Skill embeds a shared proxy authentication token directly in its distributed Python source. Anyone who can download or inspect the package can recover the token without invoking the Skill.

The _proxy and _tourmind_proxy functions place this token in the X-Proxy-Token header when authenticating to two publisher-operated Tencent Cloud Function endpoints. Although SKILL.md declares PROXY_TOKEN and HOTEL_COMPARE_PROXY_URL as environment-based configuration, the implementation does not read those environment variables and unconditionally uses the embedded endpoint and token.

Sending the token to its intended hotel proxy is not evidence of credential exfiltration. However, distributing an authentication credential in source code destroys its confidentiality and allows unrelated package recipients to reuse it outside the intended Skill workflow. The server-side scope and validity of the token were not verified during this static audit.

Attack Path

  1. An attacker downloads or otherwise obtains read access to the public Skill package.
  2. The attacker reads `scripts/hote ...[truncated 1139 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed token, treating it as compromised.
  2. Remove all authentication credentials from source code and package history.
  3. Load the proxy URL and token from HOTEL_COMPARE_PROXY_URL and PROXY_TOKEN, or retrieve them from an appropriate secret manager at runtime.
  4. Fail safely when required credentials are absent rather than falling back to a shared embedded secret.
  5. Prefer per-user or per-installation credentials over a single credential shared by every package recipient.
  6. Issue short-lived, narrowly scoped tokens that authorize only the required hotel-search routes.
  7. Enforce server-side route authorization, request quotas, rate limits, anomaly monitoring, and prompt token revocation.
  8. Add automated secret scanning to the release process to prevent credentials from being committed or packaged again.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares a network-capable tool and explicitly routes user queries through a cloud proxy to multiple external OTA platforms, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege boundaries and makes the skill's external data access less transparent to the hosting agent and reviewers, increasing the risk of unintended outbound requests or overbroad tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language docstring and all user-facing output strings are written exclusively in Chinese, indicating the skill is designed to operate in a fixed language/locale. There is no visible opt-in, language selection, or justification that this is a region-specific tool, which fits the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends user-supplied search inputs such as city, hotel name, dates, keywords, and POI data to hard-coded third-party proxy endpoints using embedded tokens, with no visible consent flow, privacy notice, or minimization. In a travel-booking context this can expose sensitive itinerary and location preferences to external services and also creates a trust boundary issue because all searches are funneled through opaque proxy infrastructure not controlled by the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.