Back to skill

Security audit

Solo Trip

Security checks across malware telemetry and agentic risk

Overview

This solo-travel skill is not malicious, but it needs review because it can install a global CLI and persist raw travel queries in a hidden local log.

Install only if you trust the FlyAI CLI and are comfortable with a global npm package being installed. Prefer approving installation manually in an isolated environment, avoid entering passport, payment, or highly sensitive travel details, disable or delete `.flyai-execution-log.json` if created, and verify safety or booking decisions through current official and local sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The playbook offers safety-focused guidance for solo female travelers without disclosing that safety assessments are limited, dynamic, and dependent on real-time local conditions. Users may over-trust the output as authoritative personal safety advice, which can result in unsafe lodging, transport, or attraction choices in a travel context where inaccurate recommendations can cause real-world harm.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The runbook explicitly records `user_query` as raw input in an internal execution log, which can capture personal data, travel dates, locations, passport/visa details, or other sensitive booking information. Storing full unredacted user input without disclosure, minimization, or retention controls creates avoidable privacy and compliance risk if logs are accessed, retained too long, or repurposed.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The runbook instructs persistent file-based logging by appending execution data to `.flyai-execution-log.json`, which can silently write user-derived data to disk. Persistent local logs increase exposure because sensitive travel or booking data may remain on disk, be backed up, or be readable by other processes or operators without the user's knowledge.

Ssd 3

Medium
Confidence
97% confidence
Finding
Taken together, the schema and persistence instructions create a system that retains raw user input in a persistent internal log. In a solo-travel and booking context, prompts may contain highly sensitive itinerary, identity, payment-adjacent, or visa-related information, so persistent retention materially increases privacy, insider-access, and breach impact.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.