Back to skill

Security audit

极限出发

Security checks for vulnerabilities and agentic risk

Overview

This travel skill is broadly coherent, but it asks for risky system installation, weakens TLS security, and persists personal travel profile data beyond what the user may expect.

Review carefully before installing. Do not run the sudo install path, prefer a pinned and sandboxed CLI version, keep TLS verification enabled, and avoid saving a persistent travel profile unless you are comfortable storing personal and family travel details locally or in memory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
reference/workflow.md:5
Finding

Unpinned Global Dependency Installation with Optional Root Privileges

Content
View full analysis

Vulnerability Details

File Location: reference/workflow.md:5-8, 16-21
Vulnerability Type: Unsafe dependency installation and privilege escalation
Risk Level: High

Vulnerable Code

bash
npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org
markdown
| npm unavailable | Ask the user to install Node.js |
| Insufficient permissions | Recommend `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` or use nvm |
| Network problem | Recommend checking the network or changing the npm registry |

Technical Analysis

The workflow requires installation or upgrade of @fly-ai/flyai-cli using the mutable latest tag. No exact version, lockfile, package integrity hash, or release verification is specified. Consequently, the code executed by the Skill can change after the Skill itself has been reviewed.

npm package installation can execute package lifecycle scripts such as preinstall, install, and postinstall. Global installation expands the modification scope beyond the project directory. The suggested sudo fallback is particularly dangerous because lifecycle scripts from the downloaded package can then execute with root privileges.

Although the configured source is the official npm registry, that does not eliminate account compromise, malicious package updates, registry compromise, or upstream supply-chain risks.

Attack Path

  1. An attacker compromises the npm package, its maintainer account, or a future release published under the package name.
  2. The malicious release becomes the version selected by the latest tag.
  3. A user invokes the Skill, which requires installation or upgrade before performing a search.
  4. npm downloads the mutable release and executes its lifecycle scripts.
  5. If the normal global installation fails due to permissions, the workflow recommends repeating the operation with sudo.
  6. The malicio ...[truncated 591 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed version rather than using @latest.
  2. Verify package integrity using a lockfile, trusted checksum, or signed release metadata.
  3. Remove the instruction to install the package with sudo.
  4. Install the dependency locally in a dedicated project directory rather than globally.
  5. Run the CLI in a restricted container or sandbox with minimal filesystem and network permissions.
  6. Disable npm lifecycle scripts where feasible, for example by using --ignore-scripts, after confirming that the package does not legitimately require them.
  7. Do not automatically upgrade the dependency whenever the Skill runs. Require explicit user approval for installation and separately reviewed upgrades.
  8. Prefer a trusted, pre-provisioned tool interface whose version is controlled by the Agent runtime.

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:84
Finding

TLS Certificate Verification Disabled for Travel Searches

Content
View full analysis

Vulnerability Details

File Location: reference/workflow.md:84-123
Vulnerability Type: Improper certificate validation
Risk Level: High

Vulnerable Code

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai <command>
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search --query "[departure city] flights departing after [time period] today within [budget]"
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight --origin "[departure city]" --destination "[destination]" --dep-date [today] --back-date [return date] --dep-hour-start [earliest departure hour] --sort-type 6
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel --dest-name "[destination]" --check-in-date [today] --check-out-date [departure date] --sort rate_desc
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi --city-name "[destination]" --poi-level 4

Technical Analysis

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 disables TLS certificate verification for Node.js HTTPS connections created by the CLI process. The client can therefore accept expired, self-signed, hostname-mismatched, or attacker-generated certificates.

The setting is applied to all documented flight, hotel, attraction, and keyword searches rather than being restricted to diagnosis. Encryption without authenticated certificates does not protect against an active man-in-the-middle attacker.

Search responses contain prices, availability data, and booking URLs that the Skill presents as clickable links. A forged response could therefore alter recommendations or substitute an attacker-controlled URL while appearing to originate from the legitimate service.

Attack Path

  1. The Agent runs a documented FlyAI command with NODE_TLS_REJECT_UNAUTHORIZED=0.
  2. An attacker controlling a network gateway, malicious Wi-Fi access point, DNS response, proxy, or routing path intercepts the connection.
  3. The attacker presents an arbi ...[truncated 956 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove NODE_TLS_REJECT_UNAUTHORIZED=0 from every command.
  2. Resolve certificate errors through correct system CA installation, proxy configuration, certificate renewal, and hostname validation.
  3. If a private CA is legitimately required, configure only that trusted CA through a narrowly scoped mechanism such as NODE_EXTRA_CA_CERTS.
  4. Fail closed when certificate verification fails; do not silently retry with validation disabled.
  5. Validate returned booking links before presentation, including the https scheme and an explicit allowlist of trusted domains.
  6. Reject URLs containing credentials, unexpected ports, deceptive subdomains, or redirects to untrusted domains.
  7. Clearly identify the final booking domain to the user before navigation.
  8. Add automated tests confirming that invalid, expired, self-signed, and hostname-mismatched certificates are rejected.

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:92
Finding

Potential Shell Command Injection Through Dynamic Search Parameters

Content
View full analysis

Vulnerability Details

File Location: reference/workflow.md:92-123
Vulnerability Type: OS command injection
Risk Level: High

Vulnerable Code

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search --query "[departure city] flights departing after [time period] today within [budget]"
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight --origin "[departure city]" --destination "[destination]" --dep-date [today] --back-date [return date] --dep-hour-start [earliest departure hour] --sort-type 6
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel --dest-name "[destination]" --check-in-date [today] --check-out-date [departure date] --sort rate_desc
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi --city-name "[destination]" --poi-level 4

Technical Analysis

These command templates interpolate values derived from users or search results into shell command strings. The workflow does not require structured process invocation, input allowlisting, or platform-correct shell escaping.

Double quotes do not reliably prevent command injection in common shells. Constructs such as command substitution, escaped quote termination, backticks, or shell-specific metacharacters may still be interpreted if the completed command is passed to a shell. For example, a malicious city value containing a command-substitution expression could cause that expression to execute before flyai receives the argument.

Dates, hour values, and sort parameters also lack explicit type and range validation. The exact exploitability depends on how the Agent runtime executes the documented templates. If it uses a shell command execution tool, the dynamic values can cross the command/data boundary.

Attack Path

  1. An attacker supplies a crafted departure city, destination, budget, time, or other search value containing shell syntax.
  2. The Agent substitutes the value into one of the docu ...[truncated 1041 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not construct shell command strings from dynamic values.
  2. Invoke the CLI through a process API that accepts an executable and an argument array, with shell processing explicitly disabled.
  3. Validate departure cities and destinations against expected Unicode text formats or a trusted city and airport database.
  4. Parse dates using a strict YYYY-MM-DD parser and reject invalid calendar values.
  5. Parse hours, prices, durations, and sort options as bounded numeric or enumerated values.
  6. Reject control characters, null bytes, newlines, and unexpected shell metacharacters in all free-form parameters.
  7. Do not treat search-result fields as trusted merely because they came from an external API.
  8. If a shell is unavoidable, use a vetted escaping library designed for the exact target shell; manual quoting is insufficient.
  9. Execute the CLI with minimal privileges, a sanitized environment, restricted filesystem access, and narrowly scoped network permissions.
  10. Add security tests containing command substitutions, quote termination, backticks, newlines, pipes, redirections, and platform-specific metacharacters.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (31)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow explicitly instructs disabling TLS certificate verification by setting NODE_TLS_REJECT_UNAUTHORIZED=0 for multiple FlyAI network commands. This removes server identity validation and enables man-in-the-middle interception or tampering of flight, hotel, and booking-link responses, which is especially dangerous because the skill later surfaces returned jumpUrl links for user booking actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill tells users to disable TLS certificate verification for CLI network requests without any warning or compensating control. Because these requests retrieve booking data and outbound links, an attacker on the network path could inject manipulated results or malicious URLs while the user is led to trust the generated travel recommendations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says to use the skill when the user mentions phrases like “现在出发”, “说走就走”, “今天能去哪”, and “突然想走”. Several of these are common conversational phrases and the file does not provide negative examples or tighter activation constraints, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and all user-facing examples are written as mandatory Chinese interaction cues, and no language choice or opt-in is offered. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs startup-time access to persistent user data via memory search and a local file fallback, which exceeds the immediate need of planning an instant departure trip. This creates unnecessary exposure of historical personal preference data and local filesystem content without an explicit user-consent step or strong minimization boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes reading stored profile data and a local profile file at startup without clearly warning the user beforehand. Silent access to persisted memory or local files undermines informed consent and can expose personal data in contexts where the user only expected ad hoc trip planning.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented 'adaptive learning' and persistent preference storage introduce ongoing profiling behavior beyond the core function of finding immediately available departures. If implemented broadly, this can accumulate sensitive travel habits, pricing sensitivity, and movement patterns that increase privacy risk and create a larger data-retention surface.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The save flow explicitly allows updating a local file for user preferences, which is unrelated to the minimal role of an instant-departure planner and can lead to unauthorized persistence of personal data. Local file modification also expands the blast radius from recommendation logic into endpoint data integrity and privacy concerns.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a narrowly scoped skill for answering 'if I leave now/X hours from now, where can I get to' by reverse-searching immediately available flights and packaging destination options. This file instead documents a generic 'ai-search' interface supporting hotels, attractions, flights, trains, and broad mixed travel intent, which does not match the claimed instant-departure-specific behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest focuses on urgent departure scenarios centered on feasible flights, destination reachability, tonight's hotel, and key attractions. The documented parameters and examples advertise broader semantic travel planning across hotels, attractions, flights, and trains, including multi-day itinerary recommendations, which expands beyond the stated 'leave now, where can I reach' skill intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill example is presented exclusively in Chinese, including user prompts and assistant responses, with no indication that language selection is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The referenced capability is a generic travel keyword search covering hotels, visas, dining, cruises, and other broad categories that are outside the skill’s stated 'instant departure' purpose. This creates a scope mismatch that can cause the agent to invoke an overly powerful or irrelevant tool based on loose travel language, leading to unintended actions, irrelevant recommendations, or prompt-routing abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The query guidance is so broad that many ordinary travel phrases can match, without guardrails tying usage to urgent departure workflows. In this skill context, that is more dangerous because the skill is supposed to answer 'leave now, where can I go' questions, yet the parameter design invites generic travel search behavior that can misroute user intent and expand the agent’s effective authority beyond its advertised scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples normalize use of the tool for broad shopping and trip-planning queries rather than immediate-departure flight discovery. In an agent setting, examples strongly shape tool selection behavior, so these unrelated examples increase the chance the skill is triggered for generic travel browsing instead of the high-urgency scenario it is supposed to handle.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents keywords, categories, city names, and all invocation examples exclusively in Chinese, which indicates the skill expects a specific language/locale. There is no accompanying note that this is China-specific or that other languages are unsupported, so the documentation effectively imposes a locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill document is written in Chinese and all example prompts, field names, and user-facing save confirmation text are Chinese-only. There is no indication that the skill supports user language preference or that Chinese is a required locale for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document defines persistent cross-platform storage of user travel profiles even though the skill's stated purpose is instant departure discovery, which can be fulfilled without long-term profiling. Persisting travel preferences and identity-adjacent data expands data collection beyond necessity, increasing privacy risk and creating unnecessary retention of personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document describes storing user profile data in memory and local files but does not include any explicit privacy notice, consent language, retention limits, or security expectations. This omission can lead to silent persistence of personal data and makes accidental overcollection or insecure handling more likely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The guidance explicitly creates a persistent local directory and stores user profile data under the home directory, establishing session persistence on disk. In this skill context, that persistence is more dangerous because it stores personal travel and family-related data outside the immediate session without clear lifecycle controls, potentially exposing it to other local processes, shared accounts, backups, or later unintended reuse.

Content

Scanner excerpt · reference/user-profile-storage.md (reported line 73)May include surrounding context.

如果 ~/.flyai/ 目录不存在,需要先创建:

bash
mkdir -p ~/.flyai

文件格式

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The schema instructs storing sensitive or highly personal attributes such as family composition, child age, home city, travel history, and special needs. These fields are not necessary for answering 'what destinations can I reach if I leave now' and materially increase harm if exposed, misused, or retained without clear consent boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The entire workflow is written as a fixed Chinese-only operating procedure and includes user-facing prompts and output templates solely in Chinese, with no indication that the user may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill requires a global npm install of a CLI and even suggests sudo for installation, which expands the attack surface beyond normal travel-search behavior and can execute untrusted package lifecycle code with elevated privileges. In an agent skill context, instructing broad system modification for a user-facing search task is unnecessary and risky, especially when it forces latest-version installs without pinning or verification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The workflow recommends using sudo npm install -g, which can execute package installation scripts as root and make system-wide changes. If the package, dependency chain, registry path, or network connection is compromised, this can lead to full host compromise rather than a contained user-level issue.

Content

Scanner excerpt · reference/workflow.md (reported line 20)May include surrounding context.

md
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |

**注意:** 此步骤只在首次使用时执行,后续调用会直接跳过已安装的情况。

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Using NODE_TLS_REJECT_UNAUTHORIZED=0 as a default workaround disables TLS certificate checks globally for that command, undermining transport security. In this skill, that means search responses and booking URLs can be spoofed or altered by an active attacker, directly affecting travel purchasing decisions.

Content

Scanner excerpt · reference/workflow.md (reported line 89)May include surrounding context.

重要:SSL 证书验证问题处理 如果遇到 "SSL 证书验证失败" 错误,需要在命令前加上环境变量:

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai <command>

3.1 广泛搜索当前可出发的航班

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

The keyword-search example bakes in TLS verification disabling for a live network request, normalizing insecure execution rather than exceptional debugging. This increases the chance that every search runs over an untrusted channel and that returned content is silently tampered with.

Content

Scanner excerpt · reference/workflow.md (reported line 96)May include surrounding context.

使用 ai-search 进行智能搜索(注:本地CLI命令为 keyword-search):

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search --query "[出发城市]出发 今天[时间段]后的航班 [预算]以内"

3.2 结构化搜索热门目的地航班

Static analysis

No suspicious patterns detected.