Back to skill

Security audit

travelkit

Security checks across malware telemetry and agentic risk

Overview

This is a coherent TravelKit flight-booking skill that uses sensitive booking and payment tools, but its high-impact actions are disclosed and gated by explicit user confirmation.

Before installing, make sure users understand that TravelKit handles real flight bookings, payments, refunds, and changes through a platform-managed API key. Users who prefer another language should explicitly request it before reviewing prices, policies, payment links, or confirmations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill hard-codes Simplified Chinese as the default reply language unless the user explicitly requests otherwise. This can create consent, comprehension, and accessibility problems, especially for users who do not read Chinese, and may cause them to misunderstand booking, payment, refund, or change details in a high-stakes travel workflow.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill mandates Chinese output for rule translation and user-facing messaging without indicating that language should follow user preference or locale. In a travel booking context, forcing a single language can cause users to misunderstand fare rules, refund/change conditions, or booking confirmations, which may lead to consent and transaction mistakes.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file hard-codes Simplified Chinese as the default consumer-facing language without any user preference check or opt-in. In a travel-booking context, this can cause users to misunderstand fares, deadlines, refund/change conditions, or required passenger data if they are not comfortable reading Simplified Chinese, which creates a real usability and consent risk even though it is not overtly malicious.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.