T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Mandatory Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This flight-search skill is not clearly malicious, but it asks agents to install and sometimes sudo-install an unpinned global CLI, force external booking links, and persist raw travel queries locally.
Review this carefully before installing. Use it only if you trust the flyai CLI and its booking links, avoid sudo installation, and be aware that the runbook may leave raw travel queries and command history in a local hidden log file.
SKILL.md:10Mandatory Commercial Output and Agent Behavior Hijacking
references/fallbacks.md:3Unpinned Global npm Installation with Root-Level Fallback
references/runbook.md:1Raw User Query Persistence and Unsafe Shell-Based Log Construction
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-flight --origin "Shanghai" --destination "Shenzhen" --dep-date 2026-04-01 --sort-type 6
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The manifest description claims a wide range of unrelated capabilities, including hotels, visas, insurance, and attractions, while the skill body is scoped to urgent flights. This mismatch can cause overbroad routing and user confusion, potentially leading the agent to invoke a flight-oriented CLI workflow for requests outside the safe, intended scope.
The activation triggers are broad, common travel phrases such as 'tomorrow' and 'urgent' that can appear in many normal conversations. This can cause the skill to activate outside its intended narrow use case, increasing the chance that an agent follows the skill’s rigid execution rules unnecessarily, including command execution or package installation prompts in unrelated contexts.
The fallback instructs the operator to retry installation with sudo npm i -g, which executes package installation as root. If the npm package, one of its dependencies, or the registry response is compromised, this can lead to full system compromise rather than a user-scoped install issue. In a skill context, embedding privileged remediation steps normalizes unsafe escalation and increases the blast radius of any supply-chain attack.
npm i -g @fly-ai/flyai-cli
flyai --version
# Fails → sudo npm i -g @fly-ai/flyai-cli
# Still fails → STOP. Do NOT answer with training data.
The trigger phrase "tonight" is extremely broad and can appear in ordinary travel conversations, making unintended activation likely. In a skill that maps natural language directly to CLI flight-search commands, this can cause the agent to execute searches without sufficiently clear user intent or confirmation.
The trigger phrase "tomorrow" is similarly overbroad and lacks constraints tying it to an explicit flight-search request. Because this skill is designed to execute CLI commands based on trigger phrases, a common word like this increases the risk of accidental tool invocation and unintended data lookups or downstream booking-related actions.
The runbook explicitly records the raw user query in an internal execution log without any notice, minimization, or redaction guidance. In a travel skill, user queries can contain sensitive personal data such as names, dates, locations, passport/visa context, or emergency travel details, so retaining raw input increases privacy and compliance risk if logs are accessed or reused.
The schema includes retention of user_query as raw input in the execution log, which directs storage of full user-provided content rather than the minimum needed for operations. For this travel-focused skill, raw queries may reveal itinerary plans, locations, companions, booking identifiers, or other personal context that should not be broadly retained.
The runbook instructs the agent to append the execution log to a local file, creating persistent storage of potentially sensitive execution data without any user warning or retention safeguards. Persistent disk logging increases exposure because the data may remain available long after the session and can be collected, leaked, or accessed by other processes or operators.
The instruction to write the full generated execution log to .flyai-execution-log.json persists user-derived data and command history to disk. This is dangerous because it expands the attack surface from transient processing to durable storage, enabling later unauthorized access, forensic recovery, or accidental inclusion in backups and support bundles.
The file explicitly states that the agent should "never answer without executing," encouraging automatic CLI invocation as the default behavior. Even though the listed commands are read-oriented flight searches, failing to disclose or gate command execution reduces user awareness and increases the chance of silent tool use on ambiguous prompts.
No suspicious patterns detected.