Back to skill

Security audit

酒店聪明订

Security checks across malware telemetry and agentic risk

Overview

This hotel comparison skill mostly does what it says, but it needs review because it embeds a proxy credential and can silently favor a commission-linked booking source when prices tie.

Install only if you are comfortable sending hotel search details to the publisher’s proxy service and treating booking links as potentially monetized. Before relying on recommendations, compare equal-price options yourself and prefer a version that removes the embedded proxy token or clearly discloses affiliate ranking and link behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
If the skill uses an embedded proxy token, affiliate-prioritized ranking, or commission-bearing booking links without clear disclosure, it can mislead users into trusting recommendations that are financially biased rather than purely price/quality driven. Hidden external service access and monetized redirects also expand the attack surface for tracking, abuse of embedded credentials, and deceptive decision support.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The script embeds a usable default proxy token in source code and automatically sends it on every outbound request. Hardcoded credentials can be extracted by anyone with code access, reused outside intended contexts, and make it difficult to rotate or scope access safely.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The advisor sorts equal-price results using a commission priority that favors RG, introducing affiliate bias not disclosed in the stated user-centric comparison purpose. This can steer users toward monetized links even when alternatives are equally good, undermining integrity and informed consent.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill claims to help users find the cheapest option, but the implementation contains tie-breaking logic that prefers a commission-bearing platform. This mismatch is dangerous because it is deceptive behavior that can manipulate user decisions while appearing objective.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
Using a hardcoded default proxy token for outbound requests without warning means the skill can silently operate with embedded credentials even when operators did not intentionally configure access. This increases the chance of credential leakage, unauthorized reuse, and unnoticed dependency on a secret shipped in code.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.