Back to skill

Security audit

飞猪旅行

Security checks across malware telemetry and agentic risk

Overview

This travel skill sends user-entered travel and location queries to disclosed external proxy/API services, with no evidence of local persistence, credential theft, destructive actions, or hidden behavior.

Before installing, understand that your travel searches, destinations, dates, hotel interests, and route/address queries may be sent to the skill publisher's Tencent SCF proxy and then to Fliggy or Gaode. Avoid entering private home addresses or sensitive itinerary details unless you are comfortable with that external processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states that user input is routed through a cloud proxy and then to Fliggy/Gaode APIs, but it does not present a clear, prominent warning that user travel queries and possible location-related data will be disclosed to third parties. Travel plans can contain sensitive personal information such as destinations, dates, companions, and inferred location patterns, so silent forwarding creates a meaningful privacy risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends user-supplied travel queries to a third-party Tencent SCF proxy and includes a hard-coded proxy token, but provides no user-facing disclosure or consent mechanism. Travel queries can contain sensitive itinerary, destination, timing, and booking-interest data, so silent transmission to external infrastructure creates a real privacy and data-governance risk even if the functional purpose is legitimate.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The Gaode proxy requests transmit precise addresses and routing inputs, which may reveal a user's current location, destination, or movement patterns, without disclosure or consent. Because routing and geocoding data is more sensitive than generic search text, undisclosed forwarding to an external proxy materially increases privacy exposure and potential misuse of location history.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.