Back to skill

Security audit

huazhuhelper

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but its example code handles Huazhu API credentials and bearer tokens in unsafe ways that need review before use.

Review before installing or using. Do not paste production clientSecret values into chat or source files; use a secret manager or environment variables. Change the hotel API endpoint to HTTPS, remove token printing, reduce OAuth scope if Huazhu supports it, and confirm the skill is being used specifically for Huazhu hotel-list queries before sending credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:45
Finding

OAuth Bearer Token Transmitted over Plaintext HTTP

Content
View full analysis
list: token = self.auth.get_token() headers = { "Authorization": f"Bearer {token}", "distributorId": self.auth.distributor_id, "timestamp": str(int(time.time() * 1000)), "traceId": str(uuid.uuid4()), } resp = requests.get(f"{self.biz_domain}/hotels", headers=headers, timeout=10) ``` ### Technical Analysis The default test configuration sends an OAuth bearer token in the `Authorization` header to an `http://` URL. Plain HTTP provides neither transport confidentiality nor server authentication. Although the preceding OAuth exchange uses HTTPS, that protection is negated when the resulting reusable token is subsequently transmitted over an unencrypted connection. This network request is necessary for the declared hotel-query functionality, but sending authentication material over HTTP exceeds acceptable minimum-risk behavior. The client also accepts an arbitrary `biz_domain` without validating its scheme or expected hostname, making accidental token disclosure to an insecure or unintended endpoint possible. ### Attack Path 1. A user supplies a Huazhu client ID and ...[truncated 1078 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:63
Finding

OAuth Access-Token Material Disclosed in Console Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:22
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description includes broad phrases like '华住API' and '查酒店', which can match loosely related requests and cause the skill to activate unexpectedly. Because this skill requests sensitive credentials and performs external API calls, accidental invocation increases the chance that users disclose secrets in the wrong context or that the agent sends requests the user did not clearly intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the user to provide a clientSecret and then uses it in code that performs outbound authentication requests, but it does not clearly warn about secret-handling, storage, logging, or transmission risks. This is especially risky because the sample code prints token material and encourages running code in the user's project environment, increasing the likelihood of credential exposure through shell history, logs, notebooks, or intercepted test traffic; additionally, the test business endpoint is configured over plain HTTP in the module example, which can expose bearer tokens in transit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.