Back to skill

Security audit

邮轮游查询预订

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent cruise search tool that sends user travel queries to a disclosed Tuniu proxy API and does not show hidden persistence, local data access, destructive behavior, or credential theft.

Install this if you are comfortable with cruise search criteria, dates, departure cities, destination keywords, and product IDs being sent to the configured Tuniu proxy service. Treat returned booking links as external checkout links and verify prices and terms on Tuniu before buying.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tainted flow: 'req' from os.environ.get (line 43, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/cruise_search.py (reported line 47)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("X-Proxy-Token", PROXY_TOKEN)
    try:
        with urllib.request.urlopen(req, timeout=120, context=ctx) as resp:
            data = json.loads(resp.read().decode("utf-8"))
            if data.get("code") == 0:
                return data.get("data", {})

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares network and environment-variable backed tool capabilities but does not define an explicit tool scope such as permissions or allowed-tools. This weakens governance around what the skill is expected to access and can lead to overbroad tool use, unauthorized outbound requests, or unintended exposure of secrets like PROXY_TOKEN through misconfiguration or future changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file consistently uses Chinese for the name, descriptions, examples, and usage guidance, which effectively forces a specific language for users. The policy allows this only when the skill offers a language choice or clearly documents a justified region-specific constraint, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file's natural-language interface is written in Chinese, including the module description and many user-visible messages, but it does not provide any language selection or opt-in. That can violate language/locale policy when users are not explicitly choosing a Chinese-only experience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends user-supplied search criteria and a secret authentication token to a remote proxy service, but the code provides no user-facing disclosure, consent boundary, or minimization of what is transmitted. In an agent setting, this can expose travel queries and operational secrets to a third-party service unexpectedly, increasing privacy and secret-handling risk even though TLS is enabled.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.