Back to skill

Security audit

Tonight Hotel

Security checks for vulnerabilities and agentic risk

Overview

This hotel-search skill is purpose-related, but it mandates a third-party CLI, forces booking-link output, and keeps hidden raw request logs without enough user control.

Review before installing. Use only in an isolated environment where a global npm install and third-party travel CLI are acceptable, avoid entering sensitive personal or payment details, and disable or remove the hidden execution log unless the publisher adds clear consent, redaction, and retention controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:8
Finding

Mandatory Agent Behavior Override and Commercial Response Injection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:36
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation
`. 2. Verify the package against an approved integrity hash, lockfile, signature, or internally mirrored artifact. 3. Require explicit informed user approval before any installation. 4. Install the package locally in an isolated temporary or project-specific environment rather than globally. 5. Disable lifecycle scripts during installation where compatible, then explicitly run only reviewed setup operations. 6. Document the registry and publisher identity expected for the package. 7. Prefer a reviewed, fixed API integration over dynamically installing an executable. 8. Re-audit the dependency and its transitive dependency tree before version changes. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
references/playbooks.md:7
Finding

Shell Command Injection Through User-Controlled CLI Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/runbook.md:7
Finding

Hidden Raw-Query Persistence and Shell Injection in Execution Logging

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The runbook states that the log is maintained internally and not shown to users. It stores the user's raw request, collected parameters, complete commands, fallback commands, and execution metadata in `.flyai-execution-log.json`. This creates two distinct security problems: 1. **Undisclosed sensitive-data retention:** Travel requests can reveal location, intended lodging dates, budgets, and other personal information. The design specifies no consent, redaction, retention period, access control, file-permission policy, or deletion procedure. 2. **Shell injection:** The generated JSON is embedded inside a single-quoted shell argument to `echo`. JSON escaping does not make text safe for shell single-quote contexts. If raw input contains a single quote, it can terminate the quoted string and introduce shell operators or co ...[truncated 1435 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

flyai search-hotel --dest-name "Shanghai" --check-in-date 2026-05-01 --check-out-date 2026-05-02 --sort price_asc

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The runbook explicitly records user_query as raw input in an internal execution log, which can capture sensitive travel data, contact details, credentials, payment-related text, or other personal information without any minimization, consent, or retention controls. In a travel-booking context, users may provide especially sensitive itinerary and identity data, so persistent logging increases privacy and compliance risk if logs are accessed, retained too long, or reused beyond the immediate transaction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation at L049 states --sort should always be price_asc, but the same file later defines valid scenarios using distance_asc and also lists multiple sort options including rate_desc and price_desc. This is an internal documentation contradiction about intended behavior, not merely an omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The runbook instructs appending execution logs to .flyai-execution-log.json, creating a persistent local record of operational data without transparency or safeguards. Even if intended for debugging, silent file persistence can expose prior requests and metadata to other processes, users, or later compromise, especially when combined with the logged raw query content described earlier.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.