Back to skill

Security audit

Hotel Price Finder - Multi OTA

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only hotel price comparison skill whose network use is consistent with finding hotel prices, with no hidden installer, persistence, or unrelated local access.

Install only if you are comfortable with hotel search details being sent to services such as Xotelo, Agoda, OTA booking sites, and optionally Apify. Do not set APIFY_API_KEY unless you trust that Apify workflow and are comfortable with its handling of your travel search parameters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance is broad enough to trigger on ordinary travel-related conversation, which can cause the agent to invoke this skill without clear user intent. That increases the chance of unnecessary external lookups and disclosure of travel queries, dates, and preferences to third-party services.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The optional Apify flow sends user travel details to a third-party scraping service but does not require clear user notice or consent. This creates a privacy and data-governance risk because destination, dates, occupancy, and related search parameters may be transmitted outside the primary platform unexpectedly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.