Back to skill

Security audit

旅伴匹配度报告

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent travel-matching purpose, but it documents unsafe installation, TLS-bypass, command-use, and profile-persistence practices that users should review before installing.

Review this skill before installing. Do not use the documented TLS-bypass command, avoid sudo/global @latest installation unless you independently trust and pin the CLI, verify any booking links before acting on them, and only allow profile saving if you are comfortable storing travel and family preference data in local plaintext or memory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:164
Finding

TLS Certificate Verification Is Explicitly Disabled

Content
View full analysis
``` ### Technical Analysis Setting `NODE_TLS_REJECT_UNAUTHORIZED=0` disables TLS certificate validation for the Node.js process. The client can consequently accept expired, self-signed, incorrectly scoped, or attacker-controlled certificates. The instruction specifically recommends this fallback after certificate verification fails. A verification failure can itself indicate interception or endpoint impersonation, making retrying without validation especially dangerous. FlyAI search requests may include travel dates, locations, budgets, family requirements, and other user preferences. Search responses also contain booking and image URLs that the Skill instructs the agent to display. ### Attack Path 1. A user invokes a FlyAI search through the Skill. 2. An attacker controlling the network, DNS resolution, proxy, or gateway causes TLS verification to fail. 3. Following the documented workflow, the agent retries with `NODE_TLS_REJECT_UNAUTHORIZED=0`. 4. The attacker presents an untrusted certificate that the client now accepts. 5. The attacker intercepts travel-profile data or modifies the FlyAI response. 6. The modified response can contain falsified prices, misleading recommendations, or attacker-controlled booking URLs. 7. The agent displays those URLs to the user as actionable booking links. ### Impact Assessment An attacker in a network interception position may obtain the confidentiality and integrity privileges associated with the FlyAI connection. This includes reading submitted travel criteria and modifying returned results. The impact is scoped to traffic and data handled by the affected Node.js process, but it can lead to phishing, fraudulent booking redirection, disclosure ...[truncated 76 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
reference/workflow.md:3
Finding

Automatic Unpinned Global Package Installation with Optional Root Privileges

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:175
Finding

User-Controlled Travel Values Are Interpolated into Shell Command Templates

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
reference/user-profile-storage.md:68
Finding

Personal Travel Profile Is Persisted in Plaintext Without Mandated Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (29)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Instructing operators to set NODE_TLS_REJECT_UNAUTHORIZED=0 disables TLS certificate validation, allowing man-in-the-middle interception or tampering with responses from backend services. In a travel skill that fetches search and booking links, this can expose users to manipulated results, phishing destinations, or leakage of travel queries and identifiers.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow explicitly instructs users to disable TLS certificate verification with NODE_TLS_REJECT_UNAUTHORIZED=0. This weakens transport security for all Node-based HTTPS connections in that process and enables man-in-the-middle attacks, package/API tampering, and interception of travel or account data. In this skill context, the instruction is especially dangerous because bypassing certificate validation is unrelated to companion matching and is presented as a routine troubleshooting step.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Recommending TLS validation bypass without a prominent safety warning normalizes an unsafe practice and directly undermines confidentiality and integrity protections. Because the workflow frames this as the fix for SSL problems, users may apply it broadly and expose subsequent searches, bookings, or credentials to interception or tampering.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill when users mention phrases such as "旅行冲突", "出行前测试", and especially "和XX一起旅行", which are broad and could arise in normal conversation without the user seeking a compatibility analysis. The file does not provide exclusion conditions or negative examples to narrow when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is written as a Chinese-only skill description and trigger set, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill encourages users toward direct booking actions via embedded links without a clear warning that links are third-party or that availability, price, and destination should be independently verified. In a commerce-adjacent workflow, this increases phishing, misdirection, and impulsive transaction risk, especially when the same skill also normalizes bypassing TLS safeguards elsewhere.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

This is an explicit insecure-default instruction: NODE_TLS_REJECT_UNAUTHORIZED=0 disables certificate verification globally for the process. That materially weakens transport security and can let attackers intercept or alter hotel, POI, or booking-link responses, which is especially dangerous in a skill that returns clickable URLs.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
| 多人旅行(3人以上)| 支持多人分别作答,取最大公约数 |
| 调和方案中的酒店/景点搜不到 | 降级为纯建议文字,不挂载具体搜索结果 |
| FlyAI 返回空结果 | 调整搜索条件或用 ai-search/keyword-search 广泛搜索 |
| SSL 证书验证失败 | 命令前加 `NODE_TLS_REJECT_UNAUTHORIZED=0` |

---

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill’s documented scope expands from compatibility analysis into hotel, flight, train, and package booking workflows, which materially increases what the skill can cause users to do. This broadening is risky because users may invoke a lightweight advice skill and instead be steered into commercial actions and additional data exposure without clear scope boundaries or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Self-growth and preference persistence are not necessary for a one-off companion-matching report and introduce unnecessary retention of user behavioral data. Because the text allows storing newly discovered preferences beyond the immediate session, the skill increases privacy and data-governance risk without strong purpose justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation mentions saving user preferences and, for non-Qoder environments, updating a local file, but does not clearly warn users that their data may be written outside the managed memory system. This creates a transparency and privacy problem because users may not realize their travel preferences or relationship-related details are being persisted locally.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Allowing newly discovered user preferences to be persisted to local storage outside the approved memory system creates a clear data-handling vulnerability. Local files may lack access controls, auditing, retention enforcement, and user deletion pathways, making sensitive preference data easier to leak or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes command examples using Chinese city names and output fields/values in Chinese, but it does not state that the skill is China-specific or offer users a language/locale option. That can violate language/locale policy by implicitly forcing a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states it will remember user travel preferences, learn from user feedback, and collect successful reconciliation cases, but provides no limits on retention, consent flow, anonymization, or privacy notice. In a travel-companion matching context, these preferences can reveal sensitive behavioral patterns and interpersonal information, making undocumented persistence and reuse a real privacy risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document defines persistent cross-session collection and storage of detailed travel-profile data for all flyai-* skills, which exceeds the narrowly stated companion-matching purpose. This creates unnecessary data retention and cross-context reuse of personal information, increasing privacy risk if the data is later accessed, repurposed, or exposed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The local filesystem mode instructs the skill to read and write a persistent user profile under ~/.flyai/user-profile.md even though local persistence is not clearly required for generating a one-time matching report. Storing travel history, family information, and preferences on disk broadens the attack surface and can expose sensitive personal data to other local processes, users, backups, or future unintended reads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown operationalizes reading and storing detailed personal profile data locally without any privacy notice, warning, or consent language about persistent local storage. Users may unknowingly cause sensitive information such as residence city, airport, child status, and travel history to be written to disk, which is a material privacy and transparency failure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The instruction to create ~/.flyai and persist profile data there establishes session persistence on the local machine, allowing personal data to survive beyond the current interaction. In this skill context, that persistence is more dangerous because the stored content includes sensitive profile details unrelated to a one-off compatibility analysis and may be reused without the user's continued awareness.

Content

Scanner excerpt · reference/user-profile-storage.md (reported line 73)May include surrounding context.

如果 ~/.flyai/ 目录不存在,需要先创建:

bash
mkdir -p ~/.flyai

文件格式

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's instructions, prompts, and output templates are all presented in Chinese, which effectively forces a specific language for the skill interaction. Under the stated policy, language constraints should either be opt-in or clearly documented as a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow requires a global npm install/upgrade of the FlyAI CLI before any search, which performs system-wide modification beyond the minimum needed for a questionnaire-style matching skill. Global installs increase supply-chain and environment integrity risk, especially when combined with always-upgrade behavior that fetches the latest package version at runtime without pinning or verification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The workflow suggests using sudo to perform a global npm install. Encouraging privileged execution for network-fetched package installation increases the blast radius of supply-chain compromise or install-script abuse, and it is unnecessary for the core purpose of a travel matching skill.

Content

Scanner excerpt · reference/workflow.md (reported line 23)May include surrounding context.

md
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络,确保可以访问 registry.npmjs.org |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs reading historical travel preferences from memory or a local file (~/.flyai/user-profile.md) without an explicit consent check, minimization guidance, or warning that personal data is being accessed. This can expose sensitive preference, location, and budget data unexpectedly, especially in shared or multi-user environments.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 creates an unsafe default by disabling certificate verification, effectively telling users to accept untrusted TLS sessions. This enables active network attackers to impersonate services, alter responses, or harvest sensitive information during CLI operations.

Content

Scanner excerpt · reference/workflow.md (reported line 168)May include surrounding context.

重要:SSL 证书验证问题处理 如果遇到 "SSL 证书验证失败" 错误,需要在命令前加上环境变量:

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai <command>

3.1 搜索折中酒店

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The only natural-language query examples are written in Chinese, which can imply the skill expects or prefers a specific language. The file does not state that other languages are supported or give users a language choice, so this may conflict with language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example says the skill will generate booking links using real hotel/attraction search data, but it gives no disclosure that external data may be fetched or that the user may be sent to third-party booking links. This can mislead users about data provenance and outbound navigation, increasing phishing, trust, and privacy risks even if the content is not overtly malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file describes the skill as supporting broad 'natural language queries for hotels, flights, etc.' and then lists open-ended categories such as 'Other' and generic examples like 'visa' or 'skiing'. Because the trigger scope is not clearly constrained and no exclusion conditions or negative examples are provided, the skill may be invoked for overly broad everyday travel-related requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.