Back to skill

Security audit

Couple Romantic Stay

Security checks for vulnerabilities and agentic risk

Overview

This travel skill is mostly about hotel search, but it asks agents to install a global third-party CLI automatically and persist raw user queries without clear user control.

Review before installing. Only use this skill if you are comfortable with a third-party FlyAI CLI being installed globally, travel searches being routed through that provider, booking links being mandatory in results, and raw query details potentially being written to a local log. Prefer installing the CLI manually in an isolated environment and disabling or removing the log persistence instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:9
Finding

Forced Commercial Output and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:35
Finding

Mandatory Installation of an Unpinned Global npm Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:94
Finding

Shell Command Injection Through User-Controlled CLI Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/runbook.md:1
Finding

Undisclosed Raw Query Persistence and Unsafe Shell-Based Log Serialization

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The runbook directs the Agent to retain the user's raw input and detailed execution activity in `.flyai-execution-log.json`, while explicitly stating that the log is not shown to users. No consent mechanism, data-minimization rule, retention period, restrictive file permission, encryption requirement, or cleanup procedure is defined. The persistence command also embeds generated JSON inside a single-quoted shell string. A user query containing a single quote can terminate that shell string when it is incorporated into `{generation_log_json}`. Additional shell syntax can then be interpreted as a command. JSON escaping does not automatically provide shell escaping, so producing valid JSON is insufficien ...[truncated 1330 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (11)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

flyai search-hotel --dest-name "Lijiang" --hotel-bed-types "大床房" --sort rate_desc --check-in-date 2026-05-20 --check-out-date 2026-05-22

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to install a global npm package automatically if the CLI is missing, which modifies the host system without explicit user approval or safety gating. In an agent context, automatic package installation expands the attack surface because package registries, install scripts, and dependency chains can execute untrusted code or alter the environment persistently.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The activation section uses generic terms like "couple," "anniversary," and "date night" without clearly constraining them to hotel-search requests. Although one negative example is given for family travel, the trigger scope is still broad and lacks more exclusion conditions, which could cause unintended activation for general travel or relationship-related queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prerequisites section directs a global npm i -g installation with no warning that it changes the local system and may run package lifecycle scripts. In a tool-using agent, this can lead to unintended persistent modification of the runtime or execution of code fetched from an external registry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This workflow makes global installation part of failure handling, meaning a simple missing-command condition triggers system modification automatically. That is more dangerous in practice because ordinary usage paths can cause the agent to fetch and run external package code without a deliberate trust decision, creating risk of supply-chain compromise and persistent host changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The fallback hard-codes a Chinese hotel type value ("民宿") rather than adapting to the user's language or locale. While not a classic security flaw, it can cause unintended behavior, misclassification, or poor user experience for non-Chinese users, and in a travel-booking context may lead to inaccurate searches or confusion about what is being booked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The runbook explicitly requires logging the raw user query and detailed per-step execution metadata, which can capture sensitive travel details, personal preferences, destinations, dates, and possibly other personal data not necessary for fulfilling a hotel-search request. For a romantic-travel skill, this is especially privacy-sensitive because queries may reveal relationship status, intimate preferences, and itinerary information, increasing the harm if logs are accessed or reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template directs collection of raw user input and persistence of that data to a local log file, while only surfacing risk flags in output rather than informing users that their queries may be retained. This creates a transparency and privacy failure: users interacting with a romance-focused travel assistant would not reasonably expect intimate travel intentions or booking details to be stored locally without notice or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The runbook instructs appending execution logs to a local file, creating durable storage of potentially sensitive interaction data without demonstrating a business need for persistent local retention. Persistent file-based logs increase exposure to unauthorized local access, accidental inclusion in backups, and later misuse beyond the travel-booking purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L150 says both to use detailUrl for booking links and to never use detailUrl, which is an active contradiction in the skill's own instructions. This creates intent-code/documentation divergence because the documented output behavior cannot be followed as written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file defines activation triggers in both English and Chinese, but does not state whether the skill is intended for bilingual use or how language selection is determined. Under the policy rule, forcing or implicitly assuming a language/locale behavior without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.