Back to skill

Security audit

全能旅行助手

Security checks across malware telemetry and agentic risk

Overview

This travel skill uses external travel and map proxy APIs as advertised, with no evidence of hidden persistence, local data access, or destructive behavior.

Install only if you are comfortable sending travel-related queries, such as cities, routes, dates, hotel preferences, and nearby-place requests, through the skill publisher's cloud proxy to travel and map services. Avoid entering sensitive personal details that are not needed for the search.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill sends raw user travel queries and related parameters to multiple third-party proxy endpoints, including cloud function URLs, without any visible consent flow, disclosure, or data-minimization controls. Travel queries can contain sensitive personal information such as origin/destination, dates, hotel preferences, and inferred whereabouts, so undisclosed transmission creates meaningful privacy and trust risk.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.