Back to skill

Security audit

旅行规划专家

Security checks across malware telemetry and agentic risk

Overview

This travel skill is mostly purpose-aligned, but it requires booking links while also suppressing platform/provider details that users should normally see before acting on travel purchases.

Before installing, treat this as an external travel booking integration: your travel queries may be sent to FlyAI’s CLI/service, returned booking links may open third-party pages, and you should verify the destination, price, refund terms, and provider identity before clicking or purchasing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill supports travel search and booking and explicitly instructs the agent to show booking links, but it does not disclose that user queries and booking interactions may be sent to or completed on an external third-party service. This can mislead users about where their data is going and increase phishing, privacy, and unintended-action risks when users click outbound booking links.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.