Back to skill

Security audit

景点智能推荐

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed travel-search helper that sends itinerary and location queries to external proxy/API services, with privacy considerations but no evidence of hidden control, persistence, destructive actions, or credential theft.

Install only if you are comfortable sending travel searches, locations, origins/destinations, and travel dates through the skill's cloud proxy to travel and map providers. It does not appear to book purchases, alter local files, or persist background behavior, but its recommendation claims are broader than the code supports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tainted flow: 'req' from os.environ.get (line 60, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/smart_poi.py (reported line 39)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except Exception as e:
        return {"error": str(e)}

Tainted flow: 'req' from os.environ.get (line 60, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/smart_poi.py (reported line 53)May include surrounding context.

python
data = json.dumps(body, ensure_ascii=False).encode("utf-8")
    req = urllib.request.Request(url, data=data, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except Exception as e:
        return {"error": str(e)}

Tainted flow: 'req' from os.environ.get (line 60, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/smart_poi.py (reported line 66)May include surrounding context.

python
method="POST",
    )
    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as r:
            return json.loads(r.read().decode("utf-8"))
    except Exception as e:
        return {"error": str(e)}

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

整体上,代码与描述的大部分核心功能是吻合的:确有6个旅游工具,覆盖景点、酒店、交通、美食、火车票、机票,并能返回图片与预订/详情链接,也确实调用了途牛和高德相关代理接口。但声明中的“暑期旅游目的地推荐,智能匹配兴趣偏好”属于更强的推荐能力主张,代码中没有看到根据用户兴趣、画像、标签、历史行为或季节进行推荐的实现,主要是参数驱动的搜索与格式化展示。因此描述对推荐智能化能力存在明显夸大。另外,代码里还包含同程代理调用函数,与“途牛+高德数据直连”这一表述不完全一致。综合判断,存在描述与实际行为不完全一致的情况,且偏差点主要集中在“智能推荐/偏好匹配”能力上。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user travel queries through a cloud proxy to third-party providers, but the user-facing description does not clearly warn users before they share itinerary, location, and travel-date information. This creates a privacy and consent risk because users may disclose sensitive travel plans without understanding the external data flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-facing docstrings, prompts, and returned messages are Chinese-only, which effectively forces a specific language without any visible user choice. The policy allows locale constraints only when explicitly justified or opt-in is provided, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill transmits user-supplied travel searches, locations, and routing data to external proxy services without any explicit user disclosure or consent mechanism. Because the queries can contain precise origin/destination and travel intent, this creates a privacy risk and expands the data-sharing surface to multiple remote services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill name, descriptions, examples, and usage guidance are entirely in Chinese, which effectively forces a specific language experience. The file does not offer user language choice or explain that the skill is intentionally limited to a Chinese-speaking or China-only audience for compliance or product reasons.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script reads PROXY_TOKEN from the environment and uses it in outbound request headers for multiple proxy calls. There is no visible user-facing notice in this file explaining that authenticated external service access is being used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.