Back to skill

Security audit

酒店智能搜索

Security checks for vulnerabilities and agentic risk

Overview

This is a hotel and nearby-food search skill that uses disclosed external proxy APIs, with notable but non-malicious documentation drift around disabled Marriott features.

Install only if you are comfortable sending hotel, restaurant, and location-related search text to the listed cloud proxy services. Expect domestic hotel search and nearby-food search to work, but treat the Marriott-specific search, detail, and package claims as currently unavailable despite being advertised.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tainted flow: 'req' from os.environ.get (line 48, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/hotel_smart_pro.py (reported line 41)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except Exception as e:
        return {"error": str(e)}

Tainted flow: 'req' from os.environ.get (line 48, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/hotel_smart_pro.py (reported line 54)May include surrounding context.

python
method="POST",
    )
    try:
        with urllib.request.urlopen(req, timeout=15) as r:
            raw = json.loads(r.read().decode("utf-8"))
            if isinstance(raw, dict) and "code" in raw:
                if raw.get("code") == 0:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description advertises five working hotel-related capabilities, but the finding indicates several Marriott functions are not actually implemented and only return service-adjustment messages. This creates a trust boundary problem: users and orchestrators may rely on unavailable behavior, route sensitive queries incorrectly, or make decisions based on misleading capability claims.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares network access and environment-backed proxy configuration but does not define any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it harder for reviewers and the platform to verify that outbound access and secret usage are constrained to the intended hotel-search functions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring states this is a '5-in-1' skill with Marriott search/details/packages, and the Marriott function docstrings still label them as search/detail/package tools. However, the corresponding functions do not execute those operations and instead return static notices that the service has been adjusted, creating a direct documentation-to-code contradiction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All user-facing docstrings and returned messages in this file are Chinese-only, which can amount to forcing a specific language without opt-in. The file does not state that the skill is intentionally limited to Chinese-speaking users or provide any mechanism for language selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User queries and derived location data are transmitted to external proxy services, including geocoding and nearby-search requests that can reveal sensitive travel intent and physical locations. The code does not provide any in-band disclosure, consent, minimization, or control over this sharing, which creates a privacy/security risk if the proxies log, retain, or misuse the data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description says the skill provides five hotel-search tools covering Marriott brand queries, hotel details, and package recommendations. In code, the three Marriott-related functions do not perform any search or lookup and instead always return a deprecation-style warning message, so the implemented behavior does not match the stated feature set.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code reads PROXY_TOKEN from the environment and sends it in request headers to external services. There is no nearby warning or explanatory comment indicating that the skill depends on a credential from the environment and transmits it to proxy endpoints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.