Back to skill

Security audit

美团旅行助手

Security checks for vulnerabilities and agentic risk

Overview

This travel-search skill mostly does what it says, but it has review-worthy issues: an embedded proxy token, inconsistent tool declarations, and external transmission of travel queries through an opaque proxy.

Review this before installing if you care about travel-query privacy or operational control. The skill sends your city and travel request to a remote proxy and ships with a built-in proxy token; the publisher should rotate that token, remove default credentials, clarify the exact tool names, and document the proxy endpoint and retention controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/meituan_travel.py:10
Finding

Hardcoded Proxy Authentication Token

Content
View full analysis

Vulnerability Details

File Location: scripts/meituan_travel.py, lines 10–11
Vulnerability Type: Hardcoded reusable credential
Risk Level: High

Vulnerable Code

python
PROXY_URL = os.environ.get("MEITUAN_PROXY_URL", "https://1439498936-5f2xpfi4t3.ap-guangzhou.tencentscf.com")
PROXY_TOKEN = os.environ.get("MEITUAN_PROXY_TOKEN", "tp_8k2mX9vQ4z")

The embedded token is subsequently used as an authentication header at lines 17–19:

python
req = urllib.request.Request(PROXY_URL, data=body, method="POST")
req.add_header("Content-Type", "application/json")
req.add_header("X-Proxy-Token", PROXY_TOKEN)

Technical Analysis

The source code contains a reusable proxy authentication token as the default value of MEITUAN_PROXY_TOKEN. Environment-variable override support does not protect the default token because anyone who can download or inspect the Skill package can recover it.

This violates secret-management and least-exposure principles. Once distributed in source code, the credential must be considered compromised regardless of whether the repository or package is later updated. An attacker can reproduce the application's authenticated HTTP requests without invoking the Skill through its intended interface.

Attack Path

  1. Obtain the publicly distributed Skill package or otherwise read scripts/meituan_travel.py.
  2. Extract the proxy URL and hardcoded token from lines 10–11.
  3. Construct an HTTP POST request to the disclosed proxy endpoint.
  4. Add the extracted token using the X-Proxy-Token header, matching the implementation at line 19.
  5. Submit requests directly to the proxy outside the Skill's intended execution path.
  6. Repeat or automate requests to consume service resources or abuse any proxy operations authorized by that token.

The exact server-side authorization scope cannot be established from the audited files, so access beyond the proxy capabilities granted t ...[truncated 619 chars]

Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed token, treating it as compromised.
  2. Remove all default credentials from source code, packaged artifacts, examples, and version-control history.
  3. Require credentials to be supplied at runtime through an approved secret manager or protected environment variable. Fail closed when no credential is configured.
  4. Issue separate credentials per deployment or user rather than sharing one package-wide token.
  5. Prefer short-lived, narrowly scoped credentials and restrict them to only the required proxy operation.
  6. Apply server-side rate limits, quotas, request validation, and abuse monitoring per credential.
  7. Review proxy logs for suspicious use of the exposed token and invalidate related sessions or derived credentials where applicable.
  8. Add automated secret scanning to development and release pipelines to block future credential disclosure.
  9. Align the documented environment-variable name with the implementation so operators can configure the replacement secret correctly.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tainted flow: 'req' from os.environ.get (line 18, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code allows the outbound destination to be controlled by the MEITUAN_PROXY_URL environment variable and sends both user travel queries and the X-Proxy-Token header to that endpoint. In a hostile or misconfigured runtime, this enables silent exfiltration of user data and credential leakage to an attacker-controlled server, which is more serious because this skill is explicitly designed to forward user-entered travel information off-box.

Content

Scanner excerpt · scripts/meituan_travel.py (reported line 22)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("X-Proxy-Token", PROXY_TOKEN)
    try:
        with urllib.request.urlopen(req, timeout=120) as resp:
            data = json.loads(resp.read().decode("utf-8"))
            if data.get("code") == 0:
                return data.get("data", {})

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares a proxy-backed environment requirement and appears to rely on networked capabilities, but it does not explicitly constrain permissions or allowed tools. This creates an authorization ambiguity where the runtime may grant broader access than users or reviewers expect, increasing the risk of over-privileged execution or data egress.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest declares only limited tools, but the documentation advertises much broader capabilities including flights, trains, tickets, itinerary planning, and a local_travel_query interface that is not reflected in the tool list. This mismatch can mislead users and security reviewers about what the skill actually invokes, making hidden behavior or undeclared backend access harder to audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is described as handling essentially any natural-language travel request without clear boundaries for when it should or should not activate. Overly broad invocation criteria can cause unintended triggering, resulting in unnecessary transmission of user queries to external travel services and confusing or incorrect task routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill transmits user-supplied city and travel query data to a remote proxy service, but this file provides no user-facing disclosure, consent, or minimization controls. Travel searches can reveal sensitive intent, location, and itinerary information, so undisclosed transmission creates a privacy and compliance risk even if the remote service is legitimate.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The example phrase is a common everyday request that could match ordinary conversation and trigger the skill too aggressively if the platform uses documentation examples as routing hints. In a skill that sends queries to an external proxy, accidental invocation can expose user travel-related text unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level natural-language description is entirely in Chinese and presents the skill as a fixed Chinese-language assistant, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.