Back to skill

Security audit

旅行保险聪明买

Security checks for vulnerabilities and agentic risk

Overview

The skill is a travel-insurance guidance tool, but it asks for a proxy token while telling users it needs no API key and does not transmit data.

Before installing, require the publisher to explain or remove PROXY_TOKEN and clarify whether user trip details can pass through any proxy or external service. Treat the insurance output as informational only, and note that the included Python tool file may not run until its syntax errors are fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documentation explicitly claims it is a 'pure knowledge-base skill' that requires no API key, yet the manifest declares primaryEnv: PROXY_TOKEN. This mismatch is security-relevant because it can mislead reviewers and users about whether external services, authenticated requests, or hidden network access are involved, weakening informed consent and trust boundaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The data-flow section states that the skill does not collect, store, or transmit user personal information to any third party, but the declared proxy-token dependency means requests may traverse a proxy or external service boundary. Even if no malicious exfiltration is shown, this inaccurate disclosure creates a privacy and compliance risk because users may share travel details under false assumptions about where their data goes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file presents the skill name and all user-facing guidance in Chinese, and the functions return Chinese-only output throughout the file. Because the skill does not offer an opt-in language selection or explain that it is intentionally limited to Chinese-speaking users, it creates a language/locale policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.