Back to skill

Security audit

travel-cn

Security checks for vulnerabilities and agentic risk

Overview

This is a China travel lookup skill whose external API and scraping examples match its stated purpose, with no hidden code, persistence, or privilege behavior found.

Before installing, understand that using the examples may send travel details such as city, route, and dates to third-party travel providers, and scraping may violate provider terms or trigger blocking. Prefer official APIs, avoid adding credentials directly into commands or scripts, and review any referenced local scripts before running them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to query third-party travel APIs and scrape travel sites using itinerary parameters such as origin, destination, dates, and city names, but it does not disclose that this information will be transmitted to external services. Travel itinerary and location data can be sensitive, and the scraping/API examples normalize sending that data off-platform without privacy notice, consent guidance, or data-handling boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The example sends flight search parameters to an external API endpoint, which constitutes transmission of potentially sensitive travel metadata to a third party. In the context of a travel skill, this is expected functionality, but it becomes risky because the documentation lacks disclosure, consent, authentication guidance, and any constraints on what user data may be sent.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

bash
# 需要合作伙伴资质
curl "https://api.ctrip.com/flight/search?from=SHA&to=PEK&date=2026-02-20"

爬虫方案

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The hotel search example transmits city and check-in data to an external Ctrip API, exposing user travel-related information to a third-party service. While external booking/search APIs are normal for this domain, the skill does not explain privacy implications, data minimization, or trust boundaries, making the transmission insufficiently safeguarded.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

携程 API

bash
curl "https://api.ctrip.com/hotel/search?city=上海&checkin=2026-02-20"

火车票查询

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written entirely in Chinese and describes the skill as a China travel information query capability, which suggests a fixed language/locale orientation without any stated user choice or opt-in. Under the policy, locale or language constraints should be explicitly optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description, headings, examples, and usage instructions are all written in Chinese, which effectively forces a specific language/locale experience. There is no indication that users can opt into another language or that the locale restriction is explicitly justified as a regional-only skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.