Back to skill

Security audit

whotels-booking

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide W Hotels search and booking results, but it under-discloses that it sends a local PROXY_TOKEN to a hardcoded external proxy service.

Review before installing if your agent environment may contain a PROXY_TOKEN or if you do not want W Hotels search parameters sent through the hardcoded Tencent SCF proxy. The skill shows no persistence or destructive behavior, but its credential and network behavior should be documented and scoped more clearly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tainted flow: 'req' from os.environ.get (line 24, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/whotels_hotel.py (reported line 34)May include surrounding context.

python
method="POST",
    )
    try:
        resp = urllib.request.urlopen(req, timeout=timeout)
        data = json.loads(resp.read().decode("utf-8"))
        if data.get("status") == "error":
            return {"success": False, "error": data.get("message", "未知错误")}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes a local Python script and the analyzer detected environment and network capabilities, but the manifest does not declare any explicit tool scope or allowed-tools boundary. This creates an authorization gap where the skill may run with broader-than-expected access, increasing the risk of unintended outbound requests, secret exposure from environment variables, or future abuse if the script behavior changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill for searching W Hotels prices, details, and package offers. Reading PROXY_TOKEN from environment variables introduces credential-handling behavior that is not part of the stated end-user purpose and is not otherwise disclosed in the manifest description.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation rule says the skill should trigger whenever the user mentions 'W酒店/W Hotels', but it does not clarify whether this applies only to hotel-booking intent versus general discussion, brand news, comparisons, or unrelated mentions. Because there are no negative examples or boundary conditions, the trigger could cause unintended invocation in broader conversations containing the brand name.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.