Back to skill

Security audit

潜水旅行助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed dive-travel assistant whose network calls are purpose-aligned, though users should understand that itinerary and location queries are sent to external proxy services.

Install only if you are comfortable sharing dive travel search details such as origins, destinations, dates, hotel stays, and location searches with the skill's cloud proxy services. If your environment has PROXY_TOKEN set, be aware that the script will use it for proxy authentication.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tainted flow: 'req' from os.environ.get (line 105, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/dive_travel.py (reported line 63)May include surrounding context.

python
headers[token_header] = PROXY_TOKEN
    req = urllib.request.Request(url, data=body, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        err = ""

Tainted flow: 'req' from os.environ.get (line 105, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/dive_travel.py (reported line 107)May include surrounding context.

python
headers[token_header] = PROXY_TOKEN
    req = urllib.request.Request(url, data=body, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        err = ""

Tainted flow: 'req' from os.environ.get (line 105, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/dive_travel.py (reported line 93)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except Exception as e:
        return {"error": str(e)}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill defines multiple network-backed travel and mapping tools and explicitly mentions cloud proxy routing, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill's external data access less transparent and harder to constrain, increasing the risk of unintended network or environment access if the runtime permits such capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill routes flight, hotel, transport, and food queries through a cloud proxy and third-party APIs, which can expose itinerary details, dates, locations, and travel preferences off-platform. Although it states the proxy does not store user data, it does not provide a clear upfront user warning or consent flow before transmitting potentially sensitive travel/location information to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language descriptions, error messages, suggestions, and CLI usage strings throughout the file are written in Chinese, which imposes a specific language on users. The file does not offer localization, language selection, or any documented justification for restricting interaction to Chinese.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Several functions send user-supplied travel data such as origins, destinations, dates, addresses, and nearby searches to external proxy services, but the skill gives no user-facing disclosure or consent boundary. In a travel assistant, that means location and itinerary data may be silently shared with third parties, creating a real privacy and trust risk even if not a classic code-execution flaw.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "") accesses a credential-like environment variable that is later attached to outbound requests. The file does not provide any user-facing notice that authentication material from the environment will be consumed for remote API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.