Back to skill

Security audit

酒店管家

Security checks for vulnerabilities and agentic risk

Overview

This hotel-management skill is purpose-aligned but needs review because it can change live prices, inventory, and orders using broad credentials without strong safeguards.

Review before installing in production. Use sandbox or test credentials first, restrict OTA/PMS keys to the minimum required permissions, lock endpoints to trusted OTA hosts, and add explicit human approval plus logging before any save, bulk price update, inventory change, or continuous order sync.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/browser_controller.js:18
Finding

Prompt Injection Through Unsanitized Browser Automation Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ota_client.js:27
Finding

Configurable OTA Endpoint Can Receive Bearer Credentials Without Host Validation

Content
View full analysis
{ const options = { hostname: new URL(this.platformConfig.endpoint).hostname, path: path, method: method, headers: { 'Content-Type': 'application/json', 'Authorization': `Bearer ${this.platformConfig.apiKey}` } }; const req = https.request(options, (res) => { let body = ''; res.on('data', (chunk) => body += chunk); res.on('end', () => resolve(JSON.parse(body))); }); req.on('error', (e) => reject(e)); if (data) req.write(JSON.stringify(data)); req.end(); }); ``` ### Technical Analysis The OTA destination endpoint can be changed through `OTA_CTRIP_ENDPOINT` or `OTA_MEITUAN_ENDPOINT`. The request handler extracts the configured hostname and sends the corresponding OTA API key in an `Authorization: Bearer` header. No allowlist binds each credential to its official OTA hostname. There is also no explicit validation of the configured scheme, hostname, or port before the authenticated request is created. Consequently, an attacker who can modify deployment configuration, but cannot directly read the OTA key, can redirect a legitimate operation to an a ...[truncated 2022 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
> 本仓库目前提供的是 **集成架构模板**。在使用前,您需要根据特定平台的 API 文档完善 `scripts/ota_client.js` 中的协议细节。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
> 本仓库目前提供的是 **集成架构模板**。在使用前,您需要根据特定平台的 API 文档完善 `scripts/ota_client.js` 中的协议细节。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares sensitive environment variables for OTA and internal PMS credentials but does not define an explicit tool scope such as permissions or allowed-tools. In a skill that performs networked state-changing operations, this increases the risk of overbroad access or unintended secret exposure because the agent's effective capabilities are not clearly constrained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports direct browser-based price changes, room availability updates, and order synchronization, all of which can alter business-critical state across OTA platforms and internal systems. Without an explicit user warning, confirmation flow, or safety guardrails, an agent may perform destructive or costly actions such as mispricing inventory, overselling rooms, or corrupting order sync state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs operators to start an automatic order-sync service that polls every 5 minutes, but it does not warn about operational risks such as duplicate ingestion, rate limits, unintended production-side effects, or the need for idempotency and monitoring. In a hotel OTA/PMS integration context, blindly enabling background sync can affect live reservations and inventory, making this more than a purely informational omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file instructs an agent to click a "保存" or "提交" button to commit a hotel price change, which is a safety-critical write operation affecting external system data. While the SOP describes the step, it does not include any caution, confirmation requirement, or user-facing warning about modifying live pricing before submission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · resources/ota_config.example.json (reported line 5)May include surrounding context.

json
ctrip: {
          apiKey: process.env.OTA_CTRIP_API_KEY,
          secret: process.env.OTA_CTRIP_SECRET,
          endpoint: process.env.OTA_CTRIP_ENDPOINT || 'https://api.ctrip.com/hotel/v1'
        },
        meituan: {
          apiKey: process.env.OTA_MEITUAN_API_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.js (reported line 22)May include surrounding context.

js
ctrip: {
          apiKey: process.env.OTA_CTRIP_API_KEY,
          secret: process.env.OTA_CTRIP_SECRET,
          endpoint: process.env.OTA_CTRIP_ENDPOINT || 'https://api.ctrip.com/hotel/v1'
        },
        meituan: {
          apiKey: process.env.OTA_MEITUAN_API_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · resources/ota_config.example.json (reported line 11)May include surrounding context.

json
meituan: {
          apiKey: process.env.OTA_MEITUAN_API_KEY,
          secret: process.env.OTA_MEITUAN_SECRET,
          endpoint: process.env.OTA_MEITUAN_ENDPOINT || 'https://api.meituan.com/hotel/v1'
        }
      },
      internalPms: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.js (reported line 27)May include surrounding context.

js
meituan: {
          apiKey: process.env.OTA_MEITUAN_API_KEY,
          secret: process.env.OTA_MEITUAN_SECRET,
          endpoint: process.env.OTA_MEITUAN_ENDPOINT || 'https://api.meituan.com/hotel/v1'
        }
      },
      internalPms: {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The config loader maps platform names only when they include the Chinese strings '携程' or '美团'. This creates a locale-specific behavior in natural-language handling without any user opt-in or documented regional justification in this file, which matches the policy's language/locale violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends order information to an internal PMS endpoint as part of synchronization, which is a network/data-transmission operation. Although there are console logs indicating the action, they do not warn about the sensitivity or privacy impact of transmitting order data, and this file contains no user-facing disclosure or confirmation beyond operational logging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Most of the user-facing instructional content is presented in Chinese, while the file does not state that the skill is limited to Chinese-speaking operators or provide an opt-in language choice. Under the policy, forcing a specific language without user choice can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill document is written in Chinese and does not indicate that other languages are supported or that the language choice is intentional and documented. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The config uses Chinese platform names ("携程", "美团") as the only visible labels, which imposes a specific language/locale in natural-language content. There is no indication that this is an opt-in regional configuration or that alternative locale labels are supported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language comments and SOP steps are written entirely in Chinese, including expected UI labels such as menus and success messages. This can impose a language requirement on users or agents without any documented opt-in or indication that the skill is intentionally limited to Chinese-language OTA backends.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.