Back to skill

Security audit

Search Cheap Flights — Low-Cost Airfare, Budget Airlines, Discount Tickets & Flight Deals

Security checks for vulnerabilities and agentic risk

Overview

This travel skill is not proven malicious, but it should go to Review because it can install and run an unpinned third-party CLI, push booking links, and persist raw user travel queries.

Install only if you are comfortable with an agent installing and running a third-party flyai CLI, sending travel queries to that provider, showing provider booking links, and writing raw query logs locally. Prefer a version that pins the dependency, removes sudo and automatic installation, validates command arguments, discloses the provider clearly, and disables raw persistent logging by default.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:11
Finding

Mandatory Third-Party Tool Usage and Promotional Output Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/fallbacks.md:3
Finding

Unpinned Global Dependency Installation with Sudo Escalation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:114
Finding

Shell Command Injection Through User-Controlled CLI Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/runbook.md:8
Finding

Unsafe Persistence of Raw Queries and Commands Through Shell-Based Logging

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The runbook instructs the agent to retain raw user input, complete commands, and fallback commands in `.flyai-execution-log.json`. Travel queries can reveal locations, dates, budgets, and itinerary information. Commands may also contain other sensitive values supplied in a query. No user consent, redaction, access-control requirement, retention period, rotation policy, or secure deletion procedure is specified. The hidden filename does not provide confidentiality. The persistence command introduces a separate shell-injection flaw. Generated JSON is ...[truncated 1895 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

flyai keyword-search --query "cheap flights Beijing to Sanya"

text

## Output Rules

1. **Conclusion first** — "Lowest ¥{min} ({airline} {flight_no}), highest ¥{max}, spread ¥{diff}."
2. **Comparison table** with ≥ 3 rows. Connecting flights show transfer city + wait time.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description claims support for flight booking, hotel reservation, train tickets, attraction tickets, itinerary planning, visa info, travel insurance, car rental, and more. However, the rest of the file documents only flyai search-flight, keyword-search, and a mention of ai-search, with explicit guidance not to activate for train tickets and no concrete hotel, visa, insurance, or car-rental workflows. This is a semantic mismatch between the advertised scope and the actual implemented skill behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to install software globally with npm i -g @fly-ai/flyai-cli and then execute it, without user confirmation or a safety warning. This creates a supply-chain and arbitrary system-modification risk: a triggered skill could change the host environment, fetch untrusted code from the network, and expand its execution surface far beyond passive travel lookup.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L017 explicitly says to never invent CLI parameters and to use only parameters listed in the Parameters Table. Yet L193 directs the agent to use flyai ai-search --query "...", even though ai-search is not defined in the Parameters section and the workflow focuses on search-flight and keyword-search. This is an active contradiction between the skill's instructions and later documentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes generic words like "cheap," "deal," "lowest price," and Chinese terms such as "便宜" and "省钱," which commonly appear in ordinary travel conversations and could cause unintended activation. Although one negative example is provided, the scope remains broad because it does not clearly constrain activation to flight-search requests versus hotels, attractions, or other budget travel topics mentioned elsewhere in the file.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
97% confidence
Finding

The file instructs the agent/operator to run sudo npm i -g @fly-ai/flyai-cli, which combines elevated privileges with installation of a package from a registry. If the package, a dependency, or the install path is compromised, this can lead to full system-level code execution and host compromise.

Content

Scanner excerpt · references/fallbacks.md (reported line 10)May include surrounding context.

bash
npm i -g @fly-ai/flyai-cli
flyai --version
# Fails → sudo npm i -g @fly-ai/flyai-cli
# Still fails → STOP. Do NOT answer with training data.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest centers this skill on finding the cheapest flights, with other travel services mentioned only as additional support. In this file, the fallback logic actively switches from flight search to train search as an alternative result path, which goes beyond the core claimed behavior of comparing flight prices and may lead the skill to provide non-flight travel outcomes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The runbook explicitly logs user_query as raw input and persists execution data to a local file, while also stating the log is internal and not shown to users. In a travel skill, user queries can contain sensitive personal and trip data such as names, locations, dates, contact details, booking intents, or visa-related information, so retaining raw queries without notice or minimization creates a real privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The runbook instructs the agent to retain raw user input in a persistent execution log via .flyai-execution-log.json, which is a direct data storage behavior rather than a hypothetical one. Because this skill handles travel planning and booking-related workflows, raw queries are especially likely to include personal, financial-adjacent, or itinerary information, increasing the sensitivity of what may be retained and later exposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template directs users to use 'flyai' and 'flyai-cli' even though the skill is described as Fliggy-powered. This provider/tool mismatch can mislead users into invoking the wrong external tool, trusting unrelated booking links, or disclosing travel data to an unintended service. In a travel-booking context, inconsistent branding and command guidance materially increases phishing, spoofing, and data-routing risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.