T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Forced Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This travel skill is mostly about hotel search, but it asks agents to install a global third-party CLI automatically and persist raw user queries without clear user control.
Review before installing. Only use this skill if you are comfortable with a third-party FlyAI CLI being installed globally, travel searches being routed through that provider, booking links being mandatory in results, and raw query details potentially being written to a local log. Prefer installing the CLI manually in an isolated environment and disabling or removing the log persistence instructions.
SKILL.md:9Forced Commercial Output and Agent Behavior Hijacking
SKILL.md:35Mandatory Installation of an Unpinned Global npm Dependency
SKILL.md:94Shell Command Injection Through User-Controlled CLI Parameters
references/runbook.md:1Undisclosed Raw Query Persistence and Unsafe Shell-Based Log Serialization
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-hotel --dest-name "Lijiang" --hotel-bed-types "大床房" --sort rate_desc --check-in-date 2026-05-20 --check-out-date 2026-05-22
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The skill instructs the agent to install a global npm package automatically if the CLI is missing, which modifies the host system without explicit user approval or safety gating. In an agent context, automatic package installation expands the attack surface because package registries, install scripts, and dependency chains can execute untrusted code or alter the environment persistently.
The activation section uses generic terms like "couple," "anniversary," and "date night" without clearly constraining them to hotel-search requests. Although one negative example is given for family travel, the trigger scope is still broad and lacks more exclusion conditions, which could cause unintended activation for general travel or relationship-related queries.
The prerequisites section directs a global npm i -g installation with no warning that it changes the local system and may run package lifecycle scripts. In a tool-using agent, this can lead to unintended persistent modification of the runtime or execution of code fetched from an external registry.
This workflow makes global installation part of failure handling, meaning a simple missing-command condition triggers system modification automatically. That is more dangerous in practice because ordinary usage paths can cause the agent to fetch and run external package code without a deliberate trust decision, creating risk of supply-chain compromise and persistent host changes.
The fallback hard-codes a Chinese hotel type value ("民宿") rather than adapting to the user's language or locale. While not a classic security flaw, it can cause unintended behavior, misclassification, or poor user experience for non-Chinese users, and in a travel-booking context may lead to inaccurate searches or confusion about what is being booked.
The runbook explicitly requires logging the raw user query and detailed per-step execution metadata, which can capture sensitive travel details, personal preferences, destinations, dates, and possibly other personal data not necessary for fulfilling a hotel-search request. For a romantic-travel skill, this is especially privacy-sensitive because queries may reveal relationship status, intimate preferences, and itinerary information, increasing the harm if logs are accessed or reused.
The template directs collection of raw user input and persistence of that data to a local log file, while only surfacing risk flags in output rather than informing users that their queries may be retained. This creates a transparency and privacy failure: users interacting with a romance-focused travel assistant would not reasonably expect intimate travel intentions or booking details to be stored locally without notice or consent.
The runbook instructs appending execution logs to a local file, creating durable storage of potentially sensitive interaction data without demonstrating a business need for persistent local retention. Persistent file-based logs increase exposure to unauthorized local access, accidental inclusion in backups, and later misuse beyond the travel-booking purpose.
Line L150 says both to use detailUrl for booking links and to never use detailUrl, which is an active contradiction in the skill's own instructions. This creates intent-code/documentation divergence because the documented output behavior cannot be followed as written.
The file defines activation triggers in both English and Chinese, but does not state whether the skill is intended for bilingual use or how language selection is determined. Under the policy rule, forcing or implicitly assuming a language/locale behavior without user opt-in can be a natural-language policy concern.
No suspicious patterns detected.