T01 · Skill Instruction Hijacking
- Location
SKILL.md:68- Finding
Mandatory Injection of Commercial Booking Links into Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This travel skill is useful in concept, but it asks for unsafe installs, weakens HTTPS security, adds broad booking behavior, and stores travel-profile data too broadly.
Review before installing. Do not run the suggested sudo/global latest install, do not use the TLS-bypass command, and avoid enabling persistent profile storage unless you are comfortable storing travel and household details locally or in memory. This skill should be fixed by pinning one verified CLI package, preserving TLS validation, limiting outputs to requested flight comparisons, validating booking-link domains, and adding clear opt-in/delete controls for saved profiles.
SKILL.md:68Mandatory Injection of Commercial Booking Links into Agent Responses
reference/workflow.md:5Execution of Mutable and Inconsistently Named Latest-Version Packages
reference/workflow.md:120TLS Certificate Verification Disabled for Flight Searches
reference/workflow.md:120User-Controlled Travel Parameters Interpolated into a Shell Command
reference/user-profile-storage.md:68Sensitive Travel and Household Profile Stored Persistently in Plaintext
Setting NODE_TLS_REJECT_UNAUTHORIZED=0 disables certificate validation for HTTPS connections, making flight-search traffic vulnerable to man-in-the-middle interception and tampering. In this skill, that could let an attacker alter pricing results, inject malicious booking URLs, or harvest any sensitive query/session data returned by the CLI or API.
The referenced file describes a broad keyword-based travel search interface rather than a capability scoped to multi-airport flight comparison. This mismatch can cause the agent to invoke an overbroad tool for queries outside its declared purpose, expanding data access and behavior in ways users and reviewers would not expect.
The referenced documentation describes train-search functionality, but the skill is declared as a multi-airport flight price comparison radar. This mismatch can cause the agent to invoke the wrong capability, produce misleading travel recommendations, or route user queries into an unintended tool flow; in an agent setting, capability confusion is a security-relevant integrity issue because it breaks expected tool boundaries.
The workflow requires users or the agent to globally install or upgrade a CLI before performing a simple airfare comparison task, which introduces unnecessary supply-chain and host-modification risk. Because this changes the execution environment and trusts a remote package source, a compromise of the package, dependency chain, or install path could lead to code execution beyond the skill's stated purpose.
The workflow normalizes disabling TLS verification for operational use and gives no warning about the resulting loss of transport authenticity. Even if intended as a workaround, this creates an unsafe default that can hide active interception and manipulated responses from the flight-search backend.
The name, description, and operating instructions are entirely in Chinese and the trigger phrases are Chinese-only, but the file does not state that the skill is region-specific or that users may choose another language. This creates a natural-language locale restriction without opt-in, which matches the policy-violation category.
The manifest describes price-matrix comparison, but the body claims persistent self-learning and user-profile storage behavior. This is a scope mismatch that can mislead users and reviewers about retention, profiling, and stateful behavior, especially because persistence is privacy-relevant and not necessary for one-off fare comparison.
The skill reads persisted user profile data at startup without clearly warning in the main skill description that it will access privacy-sensitive stored information. Startup access without prominent disclosure undermines informed consent and may surprise users who expect an on-demand comparison tool rather than a profiling system.
The skill falls back to reading a local file ~/.flyai/user-profile.md to obtain user profile data, which is not justified by the narrow purpose of multi-airport fare comparison. Local file access introduces privacy and boundary risks because it can expose persisted personal information outside the minimum data needed for the current request.
The skill is presented as a multi-airport flight price comparison tool, but it expands into hotel and attraction booking link generation. This widens the skill’s operational scope beyond user expectations, increasing the chance of unintended data use, misleading activation, and unnecessary tool access for functions not required to compare flights.
The skill instructs persistent memory updates for newly discovered preferences, which is broader than needed for airport price comparison and can lead to silent accumulation of personal travel habits. Unnecessary persistence raises privacy risk and creates opportunities for over-collection unrelated to the immediate task.
The entire skill documentation is written in Chinese and presents all user-facing prompts in Chinese, with no indication that language selection is optional or that the skill is intended only for Chinese-speaking users. Under the policy rule for natural-language violations, this creates a language/locale constraint without user opt-in or justification.
The reference file exposes a generic AI travel search interface that supports hotels, attractions, flights, trains, and mixed travel planning, which is materially broader than the skill’s declared purpose of multi-airport flight price comparison. This scope mismatch can enable capability drift or prompt routing into unintended domains, increasing the chance that the agent performs actions or returns results outside the user-approved and policy-reviewed skill boundary.
The entire example is written as a fixed Chinese-language interaction and output format, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. This can violate language/locale policy when a skill imposes a specific language without user opt-in.
The documented search supports many unrelated travel categories such as visas, hotels, dining, telecom, and cruises, giving the skill a much broader operational surface than its stated multi-airport pricing use case. In an agent setting, this creates tool-scope drift that can be abused for unintended actions or data retrieval, reducing predictability and weakening least-privilege design.
The parameter documentation requires specific Chinese-language values such as 酒店, 民宿, 客栈, 大床房, 双床房, and 多床房. This imposes a locale/language constraint in the skill interface without stating that Chinese input is required, offering alternatives, or explaining why the constraint is necessary.
The document explicitly states that the skill should remember user parameters, learn preference patterns, and accumulate past cases, which goes beyond the stated airport price-comparison function. This creates a real risk of unauthorized persistence and profiling of user data, especially because no retention limits, consent flow, or scope restrictions are described.
The markdown describes retaining user parameters and learning preferences but provides no notice about privacy, storage, sharing, retention, or deletion. In a travel-price comparison skill, this omission is significant because users may disclose location, budget, and travel habits that can be profiled over time.
The skill documentation says it will proactively provide information and predict the user's next needs, which is not part of the declared skill scope. That implies behavioral profiling and unsolicited actions based on inferred preferences, increasing privacy and trust risks if users did not expect such monitoring or recommendations.
The document promotes proactive predictions and recommendations without warning that user behavior may be profiled to drive those suggestions. Even in a benign travel assistant, undisclosed profiling can erode user trust and create privacy risk by inferring travel intent, routines, or preferences from prior interactions.
The entire skill documentation is written in Chinese and presents all user-facing examples and instructions exclusively in that language, with no indication that users can choose another language or that the skill is restricted to a Chinese-speaking context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The documentation instructs use of npx ...@latest, which fetches and executes the newest package version at runtime rather than a reviewed, pinned release. This creates a supply-chain risk: a compromised upstream package, malicious dependency update, or breaking release could execute arbitrary code in the agent environment when the skill is used.
The skill is described as a multi-airport airfare comparison tool, but the tool documentation exposes hotel, attractions, and restaurant search capabilities outside that scope. Excess capability increases attack surface and raises the chance of unintended tool use, prompt abuse, or data access beyond what users reasonably expect from this skill.
对于一个旨在比较同城不同机场出发机票价格并计算综合交通成本的技能,访问酒店、景点和餐厅数据不是直接且明显的需求。将这些能力纳入技能可执行范围,会引入与声明场景无关的广泛旅行查询能力。
The document defines persistent storage of broad user travel-profile data across platforms, including long-term preferences and history, which exceeds the narrow need of a multi-airport price comparison skill. This creates unnecessary retention of personal data and expands the privacy and misuse risk surface if the data is later accessed, correlated, or leaked.
No suspicious patterns detected.