T01 · Skill Instruction Hijacking
- Location
SKILL.md:8- Finding
Mandatory Agent Behavior Override and Commercial Response Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This hotel-search skill is purpose-related, but it mandates a third-party CLI, forces booking-link output, and keeps hidden raw request logs without enough user control.
Review before installing. Use only in an isolated environment where a global npm install and third-party travel CLI are acceptable, avoid entering sensitive personal or payment details, and disable or remove the hidden execution log unless the publisher adds clear consent, redaction, and retention controls.
SKILL.md:8Mandatory Agent Behavior Override and Commercial Response Injection
SKILL.md:36Unpinned Global Installation of a Third-Party npm Package
references/playbooks.md:7Shell Command Injection Through User-Controlled CLI Parameters
references/runbook.md:7Hidden Raw-Query Persistence and Shell Injection in Execution Logging
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-hotel --dest-name "Shanghai" --check-in-date 2026-05-01 --check-out-date 2026-05-02 --sort price_asc
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The runbook explicitly records user_query as raw input in an internal execution log, which can capture sensitive travel data, contact details, credentials, payment-related text, or other personal information without any minimization, consent, or retention controls. In a travel-booking context, users may provide especially sensitive itinerary and identity data, so persistent logging increases privacy and compliance risk if logs are accessed, retained too long, or reused beyond the immediate transaction.
The documentation at L049 states --sort should always be price_asc, but the same file later defines valid scenarios using distance_asc and also lists multiple sort options including rate_desc and price_desc. This is an internal documentation contradiction about intended behavior, not merely an omission.
The runbook instructs appending execution logs to .flyai-execution-log.json, creating a persistent local record of operational data without transparency or safeguards. Even if intended for debugging, silent file persistence can expose prior requests and metadata to other processes, users, or later compromise, especially when combined with the logged raw query content described earlier.
No suspicious patterns detected.