Back to skill

Security audit

酒店智能搜索

Security checks across malware telemetry and agentic risk

Overview

This hotel-search skill is purpose-aligned and disclosed, but users should understand that their travel and location-style search queries are sent to external proxy services.

Install only if you are comfortable sending hotel, destination, and nearby-food search terms to the skill publisher's cloud proxy and downstream Fliggy/Gaode services. Avoid entering sensitive personal details beyond what is needed for the search.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill declares and documents outbound access to external hotel and map services via a cloud proxy, yet the finding indicates no corresponding permission declaration. Undeclared network capability reduces transparency and weakens user/platform trust boundaries, especially because queries and possibly location-related terms are sent off-platform.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill states that user input flows through a cloud proxy to Fliggy and Amap, but it does not prominently warn users that hotel search terms and location-related queries are transmitted to external services. Because travel queries can reveal destination plans, current vicinity, or sensitive behavioral patterns, lack of explicit notice creates a meaningful privacy risk.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill sends user-provided hotel queries and geolocation-related inputs to third-party proxy endpoints, including a hardcoded proxy token, without any visible consent, disclosure, or minimization controls in the code. In this context, users may submit sensitive travel plans, destinations, or nearby-location searches, so silent transmission to external services creates a real privacy and data-handling risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.