Back to skill

Security audit

智能旅行助手

Security checks for vulnerabilities and agentic risk

Overview

This travel-search skill mostly does what it advertises, but it contains an explicit scan-evasion comment and under-disclosed proxy credential/data handling that should be reviewed before install.

Install only if you are comfortable with travel queries, itinerary details, and addresses being sent through the listed cloud proxy services. The maintainer should remove the scan-evasion comment, disclose the proxy endpoints and PROXY_TOKEN behavior, and correct the unavailable hotel-detail tool before this is treated as routine.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill advertises network-backed functionality and explicitly mentions a cloud proxy, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an overbroad trust boundary: the runtime may grant more capability than reviewers or users can easily verify, increasing the risk of unintended network access or environment use beyond the documented travel-search functions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment explicitly says the configuration is hardcoded to avoid triggering security scanning, which is a strong red flag because it signals deliberate evasion of security review. Even though the URLs are not secrets, designing code to bypass scanning undermines trust and can conceal risky external dependencies and unsafe deployment practices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user travel queries to third-party SCF proxy endpoints, and elsewhere also processes precise location/address inputs for geocoding and routing. In a travel assistant context, this can expose sensitive itinerary, location, and behavioral data to opaque external operators without meaningful user disclosure or consent, creating privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest and module description frame this as a ready-to-use travel assistant with integrated travel data sources, and even state '客户端零密钥'. However, the code reads PROXY_TOKEN from the environment and uses it to authenticate outbound proxy requests. While not inherently malicious, credential/environment access is not clearly justified by the user-facing travel-assistant purpose as described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code reads PROXY_TOKEN from environment variables and includes it as X-Proxy-Token in outbound requests. Accessing credentials can be safety-relevant, and this file provides no visible disclosure or warning about using environment-provided secrets for external service calls.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The brandHotelDetail docstring says it retrieves detailed hotel information, room types, and prices. The actual function performs no lookup at all and always returns a static 'service upgrading' message. This is a direct contradiction between the documented intent and the implemented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.