T01 · Skill Instruction Hijacking
- Location
scripts/browser_controller.js:18- Finding
Prompt Injection Through Unsanitized Browser Automation Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This hotel-management skill is purpose-aligned but needs review because it can change live prices, inventory, and orders using broad credentials without strong safeguards.
Review before installing in production. Use sandbox or test credentials first, restrict OTA/PMS keys to the minimum required permissions, lock endpoints to trusted OTA hosts, and add explicit human approval plus logging before any save, bulk price update, inventory change, or continuous order sync.
scripts/browser_controller.js:18Prompt Injection Through Unsanitized Browser Automation Parameters
scripts/ota_client.js:27Configurable OTA Endpoint Can Receive Bearer Credentials Without Host Validation
Referenced artifact was not completely inspected
> 本仓库目前提供的是 **集成架构模板**。在使用前,您需要根据特定平台的 API 文档完善 `scripts/ota_client.js` 中的协议细节。
Referenced artifact was not completely inspected
> 本仓库目前提供的是 **集成架构模板**。在使用前,您需要根据特定平台的 API 文档完善 `scripts/ota_client.js` 中的协议细节。
The skill declares sensitive environment variables for OTA and internal PMS credentials but does not define an explicit tool scope such as permissions or allowed-tools. In a skill that performs networked state-changing operations, this increases the risk of overbroad access or unintended secret exposure because the agent's effective capabilities are not clearly constrained.
The skill explicitly supports direct browser-based price changes, room availability updates, and order synchronization, all of which can alter business-critical state across OTA platforms and internal systems. Without an explicit user warning, confirmation flow, or safety guardrails, an agent may perform destructive or costly actions such as mispricing inventory, overselling rooms, or corrupting order sync state.
The documentation instructs operators to start an automatic order-sync service that polls every 5 minutes, but it does not warn about operational risks such as duplicate ingestion, rate limits, unintended production-side effects, or the need for idempotency and monitoring. In a hotel OTA/PMS integration context, blindly enabling background sync can affect live reservations and inventory, making this more than a purely informational omission.
This code file instructs an agent to click a "保存" or "提交" button to commit a hotel price change, which is a safety-critical write operation affecting external system data. While the SOP describes the step, it does not include any caution, confirmation requirement, or user-facing warning about modifying live pricing before submission.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
ctrip: {
apiKey: process.env.OTA_CTRIP_API_KEY,
secret: process.env.OTA_CTRIP_SECRET,
endpoint: process.env.OTA_CTRIP_ENDPOINT || 'https://api.ctrip.com/hotel/v1'
},
meituan: {
apiKey: process.env.OTA_MEITUAN_API_KEY,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
ctrip: {
apiKey: process.env.OTA_CTRIP_API_KEY,
secret: process.env.OTA_CTRIP_SECRET,
endpoint: process.env.OTA_CTRIP_ENDPOINT || 'https://api.ctrip.com/hotel/v1'
},
meituan: {
apiKey: process.env.OTA_MEITUAN_API_KEY,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
meituan: {
apiKey: process.env.OTA_MEITUAN_API_KEY,
secret: process.env.OTA_MEITUAN_SECRET,
endpoint: process.env.OTA_MEITUAN_ENDPOINT || 'https://api.meituan.com/hotel/v1'
}
},
internalPms: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
meituan: {
apiKey: process.env.OTA_MEITUAN_API_KEY,
secret: process.env.OTA_MEITUAN_SECRET,
endpoint: process.env.OTA_MEITUAN_ENDPOINT || 'https://api.meituan.com/hotel/v1'
}
},
internalPms: {
The config loader maps platform names only when they include the Chinese strings '携程' or '美团'. This creates a locale-specific behavior in natural-language handling without any user opt-in or documented regional justification in this file, which matches the policy's language/locale violation criteria.
This code sends order information to an internal PMS endpoint as part of synchronization, which is a network/data-transmission operation. Although there are console logs indicating the action, they do not warn about the sensitivity or privacy impact of transmitting order data, and this file contains no user-facing disclosure or confirmation beyond operational logging.
Most of the user-facing instructional content is presented in Chinese, while the file does not state that the skill is limited to Chinese-speaking operators or provide an opt-in language choice. Under the policy, forcing a specific language without user choice can be a natural-language policy issue.
The entire skill document is written in Chinese and does not indicate that other languages are supported or that the language choice is intentional and documented. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is justified.
The config uses Chinese platform names ("携程", "美团") as the only visible labels, which imposes a specific language/locale in natural-language content. There is no indication that this is an opt-in regional configuration or that alternative locale labels are supported.
Natural-language comments and SOP steps are written entirely in Chinese, including expected UI labels such as menus and success messages. This can impose a language requirement on users or agents without any documented opt-in or indication that the skill is intentionally limited to Chinese-language OTA backends.
No suspicious patterns detected.