Back to skill

Security audit

特色民宿

Security checks for vulnerabilities and agentic risk

Overview

This skill is a purpose-aligned Chinese homestay search tool, but it overstates some capabilities and its AI recommendation command is broken.

Install only if you are comfortable sending lodging search terms, destinations, and dates through the disclosed cloud proxy. Treat the AI recommendation and multi-platform comparison claims as unreliable until the publisher fixes the missing recommendation implementation and documents the proxy token behavior more clearly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'req' from os.environ.get (line 19, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/homestay_finder.py (reported line 29)May include surrounding context.

python
method="POST",
    )
    try:
        resp = urllib.request.urlopen(req, timeout=60)
        data = json.loads(resp.read().decode("utf-8"))
        return data.get("data", data)
    except urllib.error.HTTPError as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description broadly matches the travel lodging domain, but several core claims are overstated or unsupported by the supplied code. The implementation only accesses one backend source (Tuniu via a proxy), not multiple tourism platforms. The search capability is present, but keyword/POI-based richness is limited: keyWords and poiName are accepted yet effectively unused in the actual Tuniu query, which always searches for '民宿'. More importantly, the advertised AI recommendation capability is not implemented here because main() calls _tuniu_ai_recommend(args.query), but no such function exists in the code chunk. That makes the recommend action broken rather than functional. Finally, '零配置即装即用' is not accurate because the code relies on an external proxy endpoint and token-based header configuration. These are material description-to-behavior mismatches rather than minor implementation details.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill appears to rely on network and possibly environment-backed behavior while declaring no explicit tool scope or permission boundaries. This creates an overprivileged or opaque execution model where users and reviewers cannot clearly see what external access the skill may use, increasing the risk of unintended data egress or misuse of host-provided capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied travel search data, including destination and travel dates, to an external proxy service without any visible consent, disclosure, or minimization controls. Although this is expected for a travel search integration, undisclosed third-party transmission creates a privacy risk and may violate user expectations or platform policy if sensitive itinerary data is forwarded transparently.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command descriptions, help text, and user-facing output strings are fixed in Chinese throughout the file, which imposes a specific language on all users. There is no opt-in, locale selection, or documented justification that this skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comment and CLI help describe the recommend path as providing AI semantic homestay recommendations, but the implementation invokes _tuniu_ai_recommend(args.query), which is not defined anywhere in the file. This is an active contradiction between the documented intent and the executable behavior, because the feature will fail rather than perform the promised recommendation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.