Back to skill

Security audit

courtyard-hotel-booking

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language hotel search helper that sends search inputs to a disclosed cloud proxy, with no evidence of persistence, deception, or destructive behavior.

Install only if you are comfortable sending hotel search terms, destinations, and related query details to the configured cloud proxy. Administrators should verify PROXY_URL and PROXY_TOKEN are set only for the intended trusted proxy service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tainted flow: 'req' from os.environ.get (line 25, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code builds outbound requests to a URL taken directly from the PROXY_URL environment variable and sends both user query data and the X-Proxy-Token header to that destination. If the runtime environment is misconfigured or attacker-controlled, this enables server-side request forgery and credential exfiltration to an arbitrary endpoint, which is especially risky because the proxy token is transmitted automatically on every request.

Content

Scanner excerpt · scripts/courtyard_hotel.py (reported line 35)May include surrounding context.

python
method="POST",
    )
    try:
        resp = urllib.request.urlopen(req, timeout=timeout)
        data = json.loads(resp.read().decode("utf-8"))
        if data.get("status") == "error":
            return {"success": False, "error": data.get("message", "未知错误")}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes a cloud proxy/data aggregation flow and the analyzer detected network and environment capabilities, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates an under-specified trust boundary: the skill may access external services or environment-backed secrets without explicit user/admin review, increasing the risk of unintended data egress or misuse of hidden capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-visible strings, usage text, and returned content are consistently hardcoded in Chinese throughout the skill. There is no indication that the user can opt into this locale or that the tool is intentionally restricted to Chinese-language use, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The helper sends user-supplied hotel search parameters to the URL configured by PROXY_URL using an HTTP POST request, but there is no confirmation prompt or user-facing warning about transmitting query data to an external proxy service. Although the module docstring mentions the data source, the executable functions themselves provide no runtime disclosure for this outbound data transfer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.