全球海岛选岛助手

Security checks across malware telemetry and agentic risk

Overview

This is a coherent island travel recommendation skill with a disclosed optional booking-link lookup, not evidence of hidden or harmful behavior.

Install this if you want a Chinese-language island travel planner. Be aware it may activate on broad beach-vacation wording, and only install or use the optional flyai-cli component if you trust that package and are comfortable sending travel search terms to the Fliggy/FlyAI service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance is ambiguous because it does not define precise trigger boundaries and instead relies on an open-ended intent formulation. In context, this is more dangerous because the skill starts a structured multi-step data collection flow and may eventually query an external service, so accidental invocation can lead to unnecessary user friction and avoidable disclosure of preference and itinerary information.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance is ambiguous because it does not define precise trigger boundaries and instead relies on an open-ended intent formulation. In context, this is more dangerous because the skill starts a structured multi-step data collection flow and may eventually query an external service, so accidental invocation can lead to unnecessary user friction and avoidable disclosure of preference and itinerary information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal