Back to skill

Security audit

目的地安全指数

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, static travel-safety lookup tool with no evidence of network access, data collection, persistence, or privilege escalation.

Use this as a convenience reference for static destination-safety summaries only. Because it does not fetch live advisories despite one real-time wording claim, verify current risks with official travel advisories before making travel decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The core purpose generally aligns: the code does provide destination safety scores across five dimensions, rankings, and comparisons for 25+ destinations. However, the description materially overstates capabilities by claiming '实时风险预警' (real-time risk alerts), which the code does not implement at all—there is no networking, scheduling, alerting, or dynamic data ingestion. The script is entirely local and static. The claim of being based on authoritative data is only asserted in comments and text; the code does not access or validate such sources. Therefore this is a mismatch due to undeclared/overclaimed behavior representation, especially around real-time functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill name, descriptions, examples, and usage guidance are entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The quick-start examples present activation-style phrases such as “泰国旅游安全吗”, “东南亚哪个国家最安全”, and “法国和意大利哪个更安全” without any trigger constraints, invocation boundary, or exclusion examples. These are common natural travel questions and could cause the skill to activate in normal conversation rather than only in a clearly scoped tool-use context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file presents its purpose, usage messages, and all user-facing output exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user choice is a locale/language policy issue because non-Chinese-speaking users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.