Back to skill

Security audit

途牛旅行助手

Security checks for vulnerabilities and agentic risk

Overview

This travel assistant is purpose-aligned and discloses its proxy-based search and booking data flow, with no evidence of hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable sending travel searches and, when booking, names, phone numbers, identity-document details, and itinerary data through the configured Tencent Cloud proxy to the travel platform. Use extra care with booking and cancellation requests because those actions can create or change real travel orders.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tainted flow: 'req' from os.environ.get (line 44, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/tuniu_travel.py (reported line 48)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("X-Proxy-Token", PROXY_TOKEN)
    try:
        with urllib.request.urlopen(req, timeout=120, context=ctx) as resp:
            data = json.loads(resp.read().decode("utf-8"))
            if data.get("code") == 0:
                return data.get("data", {})

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to environment-backed authentication and networked proxy/API behavior, but does not restrict or declare tool scope via permissions or allowed-tools. This weakens least-privilege controls and makes it harder for the platform to constrain what the skill can access, increasing the blast radius if the skill implementation is modified, compromised, or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple booking and cancellation functions forward sensitive personal and travel data such as names, phone numbers, passenger details, IDs, and itinerary information to a remote proxy via _post(), but this file provides no user-facing disclosure, consent checkpoint, or data-minimization guard. In a travel-booking skill, this context increases sensitivity because the transmitted fields are sufficient to expose significant personal and trip data if users are unaware or if the proxy is misconfigured or logged excessively.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Natural-language strings throughout the file, including the module description, error messages, and formatted outputs, are fixed in Chinese. This can violate language/locale policy when a skill forces a specific language without user opt-in or an explicitly documented regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.