T09 · Insecure Skill Coding Practices
- Location
scripts/compare.py:24- Finding
Hard-Coded Reusable Proxy Credential in Distributed Source Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does hotel search and comparison as advertised, but it relies on opaque proxy services with a hard-coded shared token and overstates its price-monitoring capability.
Review this skill before installing if you are uncomfortable sending hotel names, cities, dates, and occupancy details through the publisher's proxy services. The hard-coded shared proxy token should be rotated and moved to protected configuration, and the publisher should fix the tool/CLI naming mismatches and clarify what the price-watch feature actually does.
scripts/compare.py:24Hard-Coded Reusable Proxy Credential in Distributed Source Code
代码的主要功能与“多平台酒店比价/搜索”基本一致,且确实访问了多个旅游平台代理接口进行实时价格查询与匹配。然而,声明中多次强调“降价监控”“创建降价监控任务”,这是重要能力点,但提供的代码仅包含 CLI 的 search 和 compare 两个子命令,没有 monitor/create/watch 等命令,也没有数据库、文件持久化、计划任务、价格基线比较、消息通知等任何实现。因此描述对该技能能力有实质性夸大,构成描述与实际行为不符。硬编码 token/代理地址属于实现细节,不是本次失配核心。
The skill declares executable behavior that reaches external travel platform APIs via a script and proxy service, but it does not declare any explicit tool scope, permissions, or allowed-tools boundary. This weakens host-side least-privilege controls and makes it harder to review or constrain network use, increasing the chance of unintended data egress or broader-than-expected external access.
The skill's display name, description, examples, and interaction guidance are all written exclusively in Chinese, and the file does not state that the skill is China-specific or offer an opt-in language choice. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
The manifest declares tools named compareHotelPrices, searchHotels, and createPriceWatch (L008-L047), but the usage instructions tell the agent to call compare_hotel_prices, search_hotels, and create_price_watch. This is not merely incomplete documentation: it actively directs behavior that diverges from the declared interface, which can cause the skill to fail or invoke unintended tooling.
The manifest describes the skill as supporting creation of hotel price-drop monitoring tasks, but the documented usage and implemented commands in this file only expose search and compare. No code in this file stores monitoring targets, schedules checks, or creates persistent alert tasks, so the implemented behavior is narrower than the claimed functionality.
This Python file embeds its top-level description, usage instructions, and later CLI help text entirely in Chinese, with no indication that users can select another language. That creates a natural-language locale constraint that is not documented as region-specific or presented as an opt-in choice.
The shared HTTP helper sends user-supplied travel search data to hardcoded third-party proxy endpoints using authentication headers, but there is no explicit consent flow or user-facing disclosure at the execution points. Travel itinerary, city, dates, and hotel preferences are personal behavioral data; routing them through opaque proxies increases privacy, retention, and misuse risk if those services are compromised or operated unexpectedly.
The search functions forward city, dates, occupancy, keywords, and filters to external proxy services without a clear user-visible warning at the call sites. In a travel assistant, those fields can reveal future movement plans and preferences; silent forwarding to multiple remote services materially increases privacy exposure beyond what a user may reasonably expect.
The comparison functions transmit hotel name, city, stay dates, and occupancy to external proxies to perform exact matching and pricing lookup, again without explicit disclosure in the user-facing flow. Because this is more specific than broad search data, it can reveal concrete booking intent and increase the sensitivity of the exposed information.
The Tuniu comparison path uses both detail and fallback search strategies, sending the user's selected hotel and itinerary across additional remote requests without prominent notice. This multiplies third-party exposure and can leak precise travel intent to multiple services, making the privacy risk more significant in context.
The AI-search comparison builds a natural-language query containing city, hotel, and check-in/check-out dates and sends it to an external service without explicit disclosure. Free-text transmission can expose the same sensitive itinerary data in a less structured form and may also be logged or reused by the remote AI/search provider, increasing privacy and secondary-use risk.
The compare flow sorts equal-or-close results using a commission preference that favors RG and other monetized sources, while the skill is marketed as a price-saving comparison assistant. This can bias recommendations away from the user's best interest and constitutes an undisclosed integrity issue in decision logic, especially in a commerce context where users rely on neutral ranking.
No suspicious patterns detected.