Back to skill

Security audit

同程旅行助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language travel search assistant that sends user travel queries to a disclosed cloud proxy for Tongcheng results, with no evidence of hidden persistence, local data access, destructive actions, or unrelated behavior.

Before installing, be aware that your travel searches, including cities, dates, and free-form preferences, are sent to a cloud proxy before reaching Tongcheng APIs. Avoid entering sensitive personal details in the free-form fields, and complete any booking or payment only on the official Tongcheng page reached from the returned links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares tools that use environment variables and make outbound network requests, but it does not define any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and can allow broader-than-intended access or unsafe tool invocation assumptions by the host environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest fields, examples, and usage guidance are all written in Chinese, which effectively constrains interaction to a specific language. The file does not state that Chinese is optional, offer alternative language support, or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied travel search details to a hard-coded external proxy endpoint, along with an authentication token in a header, without any visible consent, disclosure, or minimization controls in this file. Travel queries can reveal sensitive itinerary, location, and timing information, and routing them through a third-party proxy expands the trust boundary and creates privacy and data-handling risk if the proxy is compromised, logged excessively, or operated without adequate safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module title, capability description, and function docstrings are entirely in Chinese, and there is no indication that users can opt into another language or that the locale restriction is intentional for a region-specific audience. This can create a natural-language policy concern if the organization requires language choice rather than forcing a single language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.