T01 · Skill Instruction Hijacking
- Location
SKILL.md:11- Finding
Mandatory Third-Party Tool Usage and Promotional Output Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This travel skill is not proven malicious, but it should go to Review because it can install and run an unpinned third-party CLI, push booking links, and persist raw user travel queries.
Install only if you are comfortable with an agent installing and running a third-party flyai CLI, sending travel queries to that provider, showing provider booking links, and writing raw query logs locally. Prefer a version that pins the dependency, removes sudo and automatic installation, validates command arguments, discloses the provider clearly, and disables raw persistent logging by default.
SKILL.md:11Mandatory Third-Party Tool Usage and Promotional Output Hijacking
references/fallbacks.md:3Unpinned Global Dependency Installation with Sudo Escalation
SKILL.md:114Shell Command Injection Through User-Controlled CLI Parameters
references/runbook.md:8Unsafe Persistence of Raw Queries and Commands Through Shell-Based Logging
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai keyword-search --query "cheap flights Beijing to Sanya"
## Output Rules
1. **Conclusion first** — "Lowest ¥{min} ({airline} {flight_no}), highest ¥{max}, spread ¥{diff}."
2. **Comparison table** with ≥ 3 rows. Connecting flights show transfer city + wait time.
The manifest description claims support for flight booking, hotel reservation, train tickets, attraction tickets, itinerary planning, visa info, travel insurance, car rental, and more. However, the rest of the file documents only flyai search-flight, keyword-search, and a mention of ai-search, with explicit guidance not to activate for train tickets and no concrete hotel, visa, insurance, or car-rental workflows. This is a semantic mismatch between the advertised scope and the actual implemented skill behavior.
The skill explicitly instructs the agent to install software globally with npm i -g @fly-ai/flyai-cli and then execute it, without user confirmation or a safety warning. This creates a supply-chain and arbitrary system-modification risk: a triggered skill could change the host environment, fetch untrusted code from the network, and expand its execution surface far beyond passive travel lookup.
Line L017 explicitly says to never invent CLI parameters and to use only parameters listed in the Parameters Table. Yet L193 directs the agent to use flyai ai-search --query "...", even though ai-search is not defined in the Parameters section and the workflow focuses on search-flight and keyword-search. This is an active contradiction between the skill's instructions and later documentation.
The trigger list includes generic words like "cheap," "deal," "lowest price," and Chinese terms such as "便宜" and "省钱," which commonly appear in ordinary travel conversations and could cause unintended activation. Although one negative example is provided, the scope remains broad because it does not clearly constrain activation to flight-search requests versus hotels, attractions, or other budget travel topics mentioned elsewhere in the file.
The file instructs the agent/operator to run sudo npm i -g @fly-ai/flyai-cli, which combines elevated privileges with installation of a package from a registry. If the package, a dependency, or the install path is compromised, this can lead to full system-level code execution and host compromise.
npm i -g @fly-ai/flyai-cli
flyai --version
# Fails → sudo npm i -g @fly-ai/flyai-cli
# Still fails → STOP. Do NOT answer with training data.
The manifest centers this skill on finding the cheapest flights, with other travel services mentioned only as additional support. In this file, the fallback logic actively switches from flight search to train search as an alternative result path, which goes beyond the core claimed behavior of comparing flight prices and may lead the skill to provide non-flight travel outcomes.
The runbook explicitly logs user_query as raw input and persists execution data to a local file, while also stating the log is internal and not shown to users. In a travel skill, user queries can contain sensitive personal and trip data such as names, locations, dates, contact details, booking intents, or visa-related information, so retaining raw queries without notice or minimization creates a real privacy and data-retention risk.
The runbook instructs the agent to retain raw user input in a persistent execution log via .flyai-execution-log.json, which is a direct data storage behavior rather than a hypothetical one. Because this skill handles travel planning and booking-related workflows, raw queries are especially likely to include personal, financial-adjacent, or itinerary information, increasing the sensitivity of what may be retained and later exposed.
The template directs users to use 'flyai' and 'flyai-cli' even though the skill is described as Fliggy-powered. This provider/tool mismatch can mislead users into invoking the wrong external tool, trusting unrelated booking links, or disclosing travel data to an unintended service. In a travel-booking context, inconsistent branding and command guidance materially increases phishing, spoofing, and data-routing risk.
No suspicious patterns detected.