Back to skill

Security audit

全球航班查询与预订

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed travel-search helper that sends user-entered flight, hotel, and currency queries to external services, with no evidence of hidden persistence, file access, destructive actions, or unrelated data collection.

Install only if you are comfortable sending flight, hotel, flight-number, date, city, and currency-query details to the skill's cloud proxy or public exchange-rate API. Operators should keep RG_PROXY pointed at a trusted HTTPS endpoint and only set PROXY_TOKEN for that trusted proxy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tainted flow: 'req' from os.environ.get (line 25, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

_call_proxy sends user-supplied travel queries to a URL controlled by the RG_PROXY environment variable, and optionally includes a bearer token from PROXY_TOKEN. If the runtime environment is misconfigured or attacker-controlled, sensitive user itinerary data and credentials can be exfiltrated to an untrusted endpoint, and the code performs no allowlisting or trust verification of the destination.

Content

Scanner excerpt · scripts/main.py (reported line 32)May include surrounding context.

python
method="POST",
    )
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            data = json.loads(resp.read().decode("utf-8"))
            return data
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 25, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/main.py (reported line 680)May include surrounding context.

python
url = f"https://open.er-api.com/v6/latest/{from_currency.upper()}"
    try:
        req = urllib.request.Request(url)
        with urllib.request.urlopen(req, timeout=15) as resp:
            data = json.loads(resp.read().decode("utf-8"))
    except Exception as e:
        return json.dumps({"error": f"汇率查询失败: {e}"}, ensure_ascii=False)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares tools that rely on cloud/network-backed services, but it does not define an explicit tool scope such as allowed-tools or permissions. That creates unnecessary ambiguity about what external capabilities the skill may invoke, weakening least-privilege controls and making review and enforcement harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that flight, hotel, and exchange-rate queries are sent to a cloud proxy service and a public API, but it does not provide a prominent user-facing privacy disclosure at the point of use. Users may unknowingly transmit itinerary, location, and timing data to third parties, creating privacy and compliance risk if the services log, retain, or further process that data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s top-level description and all user-facing tool messages are written in Chinese, framing the skill as a China-focused travel assistant without any opt-in or alternate locale path. Because the skill also serves global flight, hotel, and exchange-rate functions, this amounts to a language/locale constraint imposed by default rather than a clearly optional or justified regional mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends flight and hotel search parameters to an external proxy service without any explicit user-facing warning or consent signal. Travel searches can reveal sensitive personal intent and itinerary data, and in this skill context the feature is expected but still privacy-relevant because the proxy endpoint is external and configurable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The exchange-rate tool sends user-selected currency pair information to a third-party API without a user-facing notice. The data is low sensitivity compared with itinerary searches, so the risk is mainly privacy/transparency rather than a severe security flaw.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.