Back to skill

Security audit

同程旅行助手

Security checks across malware telemetry and agentic risk

Overview

This travel-search skill appears purpose-aligned, but users should know their travel queries are sent to a fixed cloud proxy before reaching Tongcheng services.

Install only if you are comfortable sending travel destinations, dates, routes, and preferences to the skill publisher's cloud proxy. Avoid entering account details, identity documents, payment data, or private booking records; this skill is for search and booking links, not order management or payment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill declares and relies on outbound network access to a cloud proxy and the Tongcheng API, but the finding indicates no corresponding permission declaration. Undeclared network capability reduces transparency and security review effectiveness, making it harder for users and platforms to understand data egress and assess whether travel queries and booking-related metadata are sent off-platform.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill sends user-supplied travel queries and preferences to an external proxy service over the network, but the code provides no user-facing notice, consent mechanism, or data-handling disclosure. Travel searches can reveal sensitive location, itinerary, and timing information, so undisclosed third-party transmission creates a real privacy and trust risk even though transport is over HTTPS.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.