Back to skill

Security audit

flight-price-watcher

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its stated purpose (flight price monitoring) but the runtime code builds and runs shell commands with user-supplied values without clear sanitization, which is a risky implementation detail you should review before installing.

This skill appears to implement the advertised flight-price monitoring functionality, but review the code before installing. Key points: - Risk: Several JavaScript files build shell commands by concatenating/template-inserting user-supplied values (origin, destination, date, message text, target ID) and pass them to child_process.exec/execSync. Unsanitized input here can enable command injection on the host running the skill. Examples: monitor.js, task_manager.js, test_monitor.js use exec/execSync with interpolated strings. - What to do before installing: - Inspect the lines that call child_process.exec/execSync and ensure arguments are passed as arrays (execFile/spawn with arg arrays) or that inputs are validated/escaped. Prefer using APIs that avoid invoking a shell. - Run the skill in a restricted environment or sandbox (non-privileged user) until you're confident it is safe. - Only install FlyAI CLI from an official, trusted registry/source and verify its integrity. - Set DINGTALK_TARGET_ID to a test/staging recipient and confirm message behavior before using real accounts. - Consider limiting the filesystem directory where data/tasks.json is stored and back it up; inspect saved tasks for unexpected content. - If you want, I can point to the exact lines that build exec strings and suggest safe replacements (e.g., execFile/spawn with arg arrays or sanitization helpers).

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/task_manager.js:271