Back to skill

Security audit

ctrip-flight

Security checks for vulnerabilities and agentic risk

Overview

This flight-search skill does what it advertises, but it uses unsafe HTTPS settings and stores tracking-style cookie data locally without clear disclosure.

Review before installing. This skill sends flight search details to Ctrip, uses reverse-engineered signing code, caches generated cookie identifiers locally, and currently disables HTTPS verification. It should be fixed to use normal TLS verification and disclose or minimize cookie caching before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ctrip_flight.py:20
Finding

TLS Certificate and Hostname Verification Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/ctrip_flight.py, lines 20–22; affected request sites at lines 173 and 206
Vulnerability Type: Improper Certificate Validation
Risk Level: Medium

Complete code snippet:

python
SSL_CTX = ssl.create_default_context()
SSL_CTX.check_hostname = False
SSL_CTX.verify_mode = ssl.CERT_NONE

The insecure context is used for both HTML and API requests:

python
with urllib.request.urlopen(
    urllib.request.Request(url, headers={
        "User-Agent": UA,
        "Accept": "text/html"
    }),
    timeout=15,
    context=SSL_CTX
) as resp:
python
with urllib.request.urlopen(
    urllib.request.Request(
        f"{url}?v={random.random()}",
        data=body,
        headers=headers,
        method="POST"
    ),
    timeout=15,
    context=SSL_CTX
) as resp:

Technical Analysis

The script creates a standard TLS context but then explicitly disables hostname verification and certificate-chain validation. Consequently, HTTPS provides encryption without authenticating the remote endpoint.

This context is used when retrieving the FVP cookie from Ctrip HTML and when submitting flight-search and low-price API requests. A network-positioned attacker capable of intercepting the connection can present an arbitrary certificate without causing validation failure. The script will parse the attacker's HTML or JSON as though it came from the configured Ctrip endpoints.

Attack Path

  1. A user invokes the Skill to search for flights.
  2. The script connects to a fixed Ctrip HTTPS endpoint using SSL_CTX.
  3. An attacker controlling a relevant network path, proxy, DNS path, or compromised access point intercepts the connection.
  4. The attacker presents a forged certificate and returns crafted HTML or JSON.
  5. Because certificate and hostname verification are disabled, the response is accepted.
  6. Attacker-contro ...[truncated 847 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove both verification-disabling assignments and retain the secure defaults:
    python
    SSL_CTX = ssl.create_default_context()
    
  • Ensure check_hostname remains enabled and verify_mode remains ssl.CERT_REQUIRED.
  • Use the operating system's trusted CA store, or configure a narrowly scoped trusted CA bundle when required.
  • Fail closed on certificate, hostname, and TLS negotiation errors; do not retry using an unverified context.
  • If interception by an organizational proxy is required, install its CA through an explicit administrative trust process rather than disabling verification globally.
  • Add tests confirming that expired, self-signed, wrong-host, and untrusted certificates are rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose is simple flight search, but the implementation behavior includes anti-bot evasion techniques such as browser fingerprinting, cookie extraction, environment inspection, and token/signature generation. In context, this is risky because it materially expands the data collected and the techniques used beyond what a user would reasonably infer, and it may facilitate bypassing platform protections on a third-party service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file is heavily obfuscated and implements a client-side signature/fingerprinting routine that gathers browser environment data, plugin and WebGL/canvas/audio capabilities, cookies, storage-backed identifiers, timezone, and other entropy sources to generate a tracking/signature value. For a flight-search skill, this data collection is not necessary to fulfill the user-facing purpose and creates undisclosed surveillance and identifier linkage risk, especially if the generated token is used across sessions or requests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code enumerates and tests a broad set of browser and device characteristics, including navigator/screen properties, plugins, canvas/WebGL/audio APIs, window/document keys, timezone, and other anti-automation checks, all of which are classic fingerprinting inputs. In the context of a flight-query skill, this exceeds what is justified for searching fares and can enable covert user tracking, session correlation, and privacy-invasive profiling without clear disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script is intentionally obfuscated and accesses cookie values, storage-derived identifiers, and environment features while hiding its behavior, which prevents meaningful user or reviewer understanding of what identifiers are collected and how they are used. Obfuscation combined with undisclosed fingerprinting materially increases risk because it can conceal persistent tracking, cross-context correlation, or stealthy telemetry collection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly disables both TLS hostname verification and certificate validation for every HTTPS request by setting check_hostname = False and verify_mode = ssl.CERT_NONE. This makes all requests to Ctrip endpoints vulnerable to man-in-the-middle interception and tampering, which is especially dangerous because the script transmits cookies, request signatures, and receives flight/pricing data that could be modified in transit.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This finding is valid for the same reason: all outbound HTTPS traffic uses an SSL context that suppresses certificate and hostname checks. In this skill's context, the danger is elevated because it automates repeated API requests and includes persistent cookies in headers, so a network attacker could impersonate the remote service, capture identifiers, or return manipulated fare data without the user noticing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill appears to perform network access and likely reads bundled files and writes output, but it declares no explicit tool scope or permissions. That creates a least-privilege and transparency problem: an agent may invoke a network-capable skill without clear policy boundaries, increasing the chance of unintended external data disclosure or broader filesystem access than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description contains broad activation language like any mention of Chinese city pairs with travel dates, which can cause over-triggering. That can send user travel queries to an external service in situations where the user did not explicitly intend to use this skill, increasing privacy risk and the chance of unnecessary third-party data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not inform users that it sends travel search details to Ctrip, despite the core function requiring external requests. For a travel skill, origin, destination, and dates can be sensitive behavioral data, so lack of disclosure undermines informed consent and makes the external transmission more dangerous in this context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists cookie-related state, including a composed Cookie header and tracking identifiers, to .cookie_cache.json on disk without any notice, consent, or access controls. While not as severe as code execution, this can expose session-like identifiers and browsing/tracking data to other local users or processes, and it increases privacy risk by retaining data longer than necessary.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ctrip_flight.py:19