Back to skill

Security audit

Qb Travel Expert

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only travel advice skill with a deliberately strict critical tone, and it does not request access to files, credentials, commands, accounts, or background services.

Install this if you want a harsh expert travel critic rather than neutral trip planning. Users who want beginner-friendly, culturally neutral, or softer recommendations should explicitly ask the agent to change tone and perspective.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to reject a particular cultural/locale perspective and replace it with a mandated 'internationalized' standard, without checking whether the user wants that framing. This can bias outputs, alienate users, and cause the agent to impose value judgments tied to culture or identity rather than responding neutrally to user intent.

Static analysis

No suspicious patterns detected.