Back to skill

Security audit

机票聪明买

Security checks for vulnerabilities and agentic risk

Overview

This flight-shopping skill makes disclosed external price-lookup requests and does not show hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable sharing flight search details such as cities and dates with the skill's proxy service and providing a PROXY_TOKEN for that service. Do not expect it to purchase tickets directly, and treat the multi-platform comparison and monitor features as limited by the current script behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tainted flow: 'req' from os.environ.get (line 322, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/compare.py (reported line 324)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=HEADERS, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        err = ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares network and environment-variable-related capabilities in its content and safety statement, but it does not define any explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where a host agent may grant broader access than users expect, increasing the risk of unintended outbound requests or misuse of secrets like PROXY_TOKEN.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes example opening phrases such as "北京飞上海7月1号" and "下周哪天飞上海最便宜" without any explicit activation boundaries, exclusions, or statement of when the skill should or should not be invoked. Because these are natural everyday travel requests, they create an ambiguous trigger scope that could cause unintended activation in general conversation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends user itinerary details such as origin, destination, and travel date to third-party Tencent SCF proxy endpoints. Even over HTTPS, this is still a privacy and data-sharing issue because users are not informed that their travel data is being transmitted off-tool to external services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest and module documentation describe multi-platform price comparison, but cmd_search queries both 途牛 and RG then only appends 途牛 results into all_flights. The output still includes RG metadata in sources, so the implemented behavior does not actually perform the advertised cross-platform comparison in returned search results or lowest-price advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language instructions, examples, and user guidance are all presented in Chinese, and the file does not indicate that users may choose another language or that the locale restriction is intentional and documented. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module description and command help are presented in Chinese only, which imposes a specific language without indicating user choice or locale scoping. Under the policy, forcing a language without opt-in can be a natural-language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level docstring shows a 'compare' command usage example, but the CLI parser only defines search, calendar, and monitor subcommands and has no compare implementation. This is an active documentation-to-code contradiction about the skill's available behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code reads PROXY_TOKEN from environment variables and includes it in the X-Proxy-Token request header, but the file provides no warning or disclosure that credentials are sourced from the environment and used for outbound requests. Access to sensitive environment-based credentials should be documented or surfaced to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.