Back to skill

Security audit

amidyfortest

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent travel assistant, but its shell-style invocation can expose users to command injection and it sends full travel queries to a production HTTP backend by default.

Review this before installing. Use it only with a trusted backend, prefer an HTTPS endpoint and non-production environment unless production access is intentional, avoid entering sensitive personal or payment details, and ensure the agent invokes the Python script with structured arguments rather than interpolating user text into a shell command.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:28
Finding

Shell Command Injection Through Unsafe User Query Interpolation

Content
View full analysis
" \ --user-id "${BOOKING_API_USER_ID:-624e5b8b3f4a2f4ec566e3d3}" \ --env "${BOOKING_API_ENV:-prod}" \ --base-url "${BOOKING_API_BASE_URL:-http://host.docker.internal:8763}" ``` ```text - The `--query` value should be the user's **full original message** (do not rewrite or simplify) - The script outputs the assistant's reply to stdout; pass it back to the user verbatim ``` ### Technical Analysis The skill instructs the agent to insert the user's complete, unmodified message into a shell command inside double quotes. Double-quoted shell strings do not neutralize command substitutions such as `$(command)` or backticks. A message containing a closing quote can also terminate the argument and introduce shell operators. The Python script itself receives `--query` through `argparse` and does not invoke a shell. The vulnerability arises when an agent follows the documented shell template by constructing a command string and passing it to a shell rather than invoking the script with a structured argument array. For example, a travel-related message containing `$(attacker_command)` could be inserted into the documented command. If evaluated by a shell, the command substitution would run before Python receives the final argument. ### Attack Path 1. An attacker submits a travel query that includes shell metacharacters, command substitution, or quote-breaking syntax. 2. The skill is activated because the message also contains a flight, train, hotel, or travel request. 3. Following `SKILL.md`, the agent copies the complete original message into the `--query ""` portion of a shell command. 4. The execution environment evaluates the constructed command through a shell. 5. The shell executes the injected command before or along ...[truncated 756 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/query.py:43
Finding

Sensitive Travel Queries Transmitted Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a Python script that uses both environment-derived configuration and network access, but the manifest declares no explicit tool scope or permissions boundary. That makes the skill's effective capabilities implicit, reducing auditability and increasing the chance it is run in contexts where operators or users do not realize it can exfiltrate data to a backend service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation description and trigger list are written as Chinese-only examples and cues, which can impose a specific language expectation on users without stating that the skill is region-specific or offering alternative language support. This is a natural-language locale constraint that is not justified in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to forward the user's full original message verbatim to a backend service, but provides no privacy notice or guidance to avoid sending unnecessary sensitive data. Travel requests commonly contain personal, financial, location, or itinerary details, so unrestricted forwarding increases the risk of privacy leakage and accidental disclosure to the remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation states that the default environment is prod and labels it as production data, but does not warn that actions or queries may touch real booking systems or real user records. In a travel-booking context, using production by default can expose live customer data or trigger unintended real-world effects if the backend supports modifications or stateful operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code builds a POST request containing the user's query, user ID, and environment, then sends it to a FastAPI service. Although the module docstring states that it calls the endpoint, there is no explicit user-facing warning or disclosure that potentially sensitive travel queries and identifiers will be transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The user-facing documentation and examples are written entirely in Chinese, including the example query and usage text, with no indication that other languages are supported. This can constitute a language/locale policy issue when a skill implicitly forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.