Back to skill

Security audit

酒店聪明订

Security checks for vulnerabilities and agentic risk

Overview

The skill does hotel price comparison as advertised, but it embeds a shared proxy token and has undisclosed commission-linked tie-breaking that can steer booking links.

Review this before installing if you need neutral booking advice. The skill will send hotel search details such as city, dates, keywords, and hotel names to external proxy services, and some booking links or equal-price recommendations may favor a commission-bearing platform. The publisher should remove the embedded shared token, disclose affiliate/commission behavior, and document the proxy hosts and data handling more explicitly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/compare.py:24
Finding

Hard-Coded Proxy Authentication Token

Content
View full analysis

Vulnerability Details

File Location: scripts/compare.py, lines 24-34 and 397-402
Vulnerability Type: Hard-coded credential exposure
Risk Level: High

Vulnerable Code

python
PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z")

SCF_FLIGGY_URL = "https://1439498936-6sysdjjt99.ap-guangzhou.tencentscf.com"
SCF_TUNIU_URL = "https://1439498936-0junm3maxj.ap-guangzhou.tencentscf.com"
SCF_RG_URL = "https://1439498936-460a7b6oqn.ap-guangzhou.tencentscf.com"
SCF_HOTEL_URL = "https://1439498936-4wdncmn2oj.ap-guangzhou.tencentscf.com"

HEADERS = {
    "Content-Type": "application/json",
    "X-Proxy-Token": PROXY_TOKEN,
}

The token is attached to outbound requests as follows:

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
req = urllib.request.Request(url, data=data, headers=HEADERS, method="POST")
try:
    with urllib.request.urlopen(req, timeout=timeout) as r:
        return json.loads(r.read().decode("utf-8"))

Technical Analysis

The script embeds a proxy authentication token as the fallback value when the PROXY_TOKEN environment variable is absent. Because the project package is distributed to users, this value must be treated as publicly exposed rather than secret.

The same credential is sent in the X-Proxy-Token header to four publicly reachable Tencent SCF endpoints. An attacker who obtains the package can extract the token without executing the Skill and replay it independently of the intended client. The effective scope depends on server-side authorization, validation, and rate limiting, which are not present in the audited repository and therefore cannot be verified.

Using an environment-variable override does not mitigate the exposure because the embedded fallback remains active in default installations.

Attack Path

  1. Download or otherwise obtain the publicly distributed Skill package.
  2. Inspect scripts/compare.py and extract the default PROXY_TOKEN value and SCF endpoint URL ...[truncated 1236 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed token immediately. Assume it has already been copied from every published version containing it.
  2. Remove the fallback credential from source code. Fail closed when no credential is configured:
    python
    PROXY_TOKEN = os.environ.get("PROXY_TOKEN")
    if not PROXY_TOKEN:
        raise RuntimeError("PROXY_TOKEN must be configured securely")
    
  3. Provide credentials through an approved secret manager or protected runtime injection mechanism rather than package files, source control, command-line arguments, or logs.
  4. Issue short-lived, per-user or per-installation credentials instead of one shared static token. Support revocation and automatic rotation.
  5. Apply server-side least privilege. Allow only the request types and upstream APIs required by this Skill, and reject unknown operations and parameters.
  6. Enforce rate limits and quotas per identity, user, and source to reduce cost and denial-of-service exposure.
  7. Validate all proxy requests server-side rather than treating possession of the shared header value as sufficient authorization.
  8. Monitor for abuse of the exposed token and review historical logs for unusual request volume, unsupported operation types, or unexpected source addresses.
  9. Add automated secret scanning to source-control and release pipelines to prevent credentials from being republished.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tainted flow: 'req' from os.environ.get (line 400, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/compare.py (reported line 402)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=HEADERS, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=timeout) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        return {"error": f"HTTP {e.code}", "detail": e.read().decode("utf-8", errors="replace")}

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This is a genuine transparency and integrity issue: the skill claims to be a neutral booking-decision assistant, but the detected behavior includes embedded proxy authentication, commission-priority tie-breaking, and returning commission-linked booking URLs that can bias recommendations. In a travel-booking context, hidden monetization and undeclared routing of user queries to authenticated third-party infrastructure can mislead users, undermine trust, and expose request data to services they did not knowingly consent to.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill advertises external data access through multiple travel platforms and a proxy service, but it does not declare any explicit tool scope or permissions boundaries. That makes the network and environment capabilities less transparent to the host and reviewers, increasing the chance of overbroad access or unexpected behavior if the implementation uses hidden env values or unrestricted outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file provides natural-language opening phrases such as “上海7月1号到3号住哪便宜” and “下周哪天住外滩最便宜” as activation-style examples, but it does not define any explicit trigger scope, exclusion conditions, or narrower invocation constraints. Those phrases resemble normal conversational travel requests, which increases the risk of unintended invocation in broader chat contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description and usage examples are presented entirely in Chinese, and the rest of the CLI help text follows the same single-locale pattern. There is no indication that users may choose another language or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

A hardcoded fallback proxy token means anyone with access to the code can reuse the credential to call the backend proxy services, potentially consuming paid resources or accessing protected upstream integrations. Embedding credentials in source also makes secret rotation and incident response harder.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The RG comparison path is described as exact price comparison but also returns booking/commission links, and later ranking logic gives commission-bearing platforms preferential treatment. This mismatch between stated purpose and actual behavior can mislead users into trusting recommendations that are partially monetization-driven.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When prices are equal, the code explicitly ranks results by a commission priority that favors RG over other platforms. In a tool advertised as unbiased hotel price comparison and booking advice, this creates a hidden conflict of interest that can manipulate user decisions and steer bookings toward revenue-generating links.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The argparse description and argument help messages are all hardcoded in Chinese. This imposes a specific language/locale on all users without any opt-in, fallback, or documented regional limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.