Back to skill

Security audit

travel-route-planner

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward travel route planning skill with expected external travel/search lookups and no evidence of hidden execution, persistence, credential access, or destructive behavior.

Installers should treat this as a normal travel-planning helper. Before using live travel/search integrations, avoid sharing unnecessary personal details and confirm before taking any real booking or purchase action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is broadly phrased and could activate on many ordinary travel-planning requests without clear boundaries on when it should or should not be used. Over-broad invocation increases the chance of unnecessary tool use and unintended sharing of user itinerary details with downstream services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section instructs the agent to use travel and web_search tools to retrieve flights, hotels, weather, and traffic data, but it does not disclose that user itinerary information may be transmitted to external services. That creates a privacy and consent risk, especially when destinations, dates, and travel preferences may reveal sensitive personal plans.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The integration section says the skill obtains flight, hotel, ticket, and transport information from another skill and external search, but it omits any warning about third-party access or handling of travel-related personal data. In the travel context, booking-related queries can expose location history, future movements, and budget/preferences, making the omission materially relevant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and presents all guidance exclusively in that language, with no indication that the user can choose another language or that the skill is intended only for Chinese-speaking users. This creates a natural-language locale policy concern because it effectively imposes a language choice without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing documentation and output strings exclusively in Chinese, including the script description and usage expectations. That can violate a language/locale policy when no user opt-in or explicit region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill description and instructions are entirely in Chinese, which effectively imposes a language/locale on the user without any opt-in or stated regional justification. This can violate language-choice policy when the skill is intended for general use rather than a clearly documented Chinese-only audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.