Back to skill

Security audit

国内航班查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese domestic flight lookup tool, but users should understand that flight queries and a proxy token are sent to a cloud proxy service.

Install only if you are comfortable with your domestic flight search terms being sent through the skill publisher's hardcoded cloud proxy to access Tuniu data. Treat the advertised filtering/sorting features as potentially limited, and do not put unrelated sensitive information into flight search queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'req' from os.environ.get (line 24, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/domestic_flight.py (reported line 26)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except Exception as e:
        return {"error": str(e)}

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

该技能的核心行为与声明大体相关:它通过腾讯云 SCF 代理访问途牛航班数据,执行机票查询并展示价格、时刻、航司等信息,因此主用途基本匹配“国内航班查询”。但存在两处明显描述与实现不一致。第一,声明强调“支持直飞和中转筛选”,而代码只是将返回结果按 journeyType 分成“直飞航班”和“中转航班”分别展示,没有任何输入参数或过滤逻辑让用户筛选只看某一类。第二,格式化输出中固定加入“推荐酒店/景点/市内交通”附加服务文案,这超出了声明中单纯航班查询的范围。综合看,虽然主功能一致,但声明对能力有实质性夸大,并包含少量未声明的扩展内容,因此应判定为存在不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name, description, examples, and usage guidance are entirely in Chinese, and the file does not state that the skill is region- or language-specific by design beyond covering domestic flights. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends user travel queries and an authentication token to a third-party proxy service, but the code provides no user-visible notice or consent mechanism. In a plugin context, this can expose itinerary data and operational secrets to an external service unexpectedly, increasing privacy and supply-chain risk if the proxy is compromised or untrusted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings, docstrings, and user-visible responses throughout the file are written in Chinese, and the file does not indicate that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking context. That can violate the language/locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.