Back to skill

Security audit

同城不同价

Security checks for vulnerabilities and agentic risk

Overview

This travel skill is useful in concept, but it asks for unsafe installs, weakens HTTPS security, adds broad booking behavior, and stores travel-profile data too broadly.

Review before installing. Do not run the suggested sudo/global latest install, do not use the TLS-bypass command, and avoid enabling persistent profile storage unless you are comfortable storing travel and household details locally or in memory. This skill should be fixed by pinning one verified CLI package, preserving TLS validation, limiting outputs to requested flight comparisons, validating booking-link domains, and adding clear opt-in/delete controls for saved profiles.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:68
Finding

Mandatory Injection of Commercial Booking Links into Agent Responses

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
reference/workflow.md:5
Finding

Execution of Mutable and Inconsistently Named Latest-Version Packages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:120
Finding

TLS Certificate Verification Disabled for Flight Searches

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:120
Finding

User-Controlled Travel Parameters Interpolated into a Shell Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
reference/user-profile-storage.md:68
Finding

Sensitive Travel and Household Profile Stored Persistently in Plaintext

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (38)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 disables certificate validation for HTTPS connections, making flight-search traffic vulnerable to man-in-the-middle interception and tampering. In this skill, that could let an attacker alter pricing results, inject malicious booking URLs, or harvest any sensitive query/session data returned by the CLI or API.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The referenced file describes a broad keyword-based travel search interface rather than a capability scoped to multi-airport flight comparison. This mismatch can cause the agent to invoke an overbroad tool for queries outside its declared purpose, expanding data access and behavior in ways users and reviewers would not expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The referenced documentation describes train-search functionality, but the skill is declared as a multi-airport flight price comparison radar. This mismatch can cause the agent to invoke the wrong capability, produce misleading travel recommendations, or route user queries into an unintended tool flow; in an agent setting, capability confusion is a security-relevant integrity issue because it breaks expected tool boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow requires users or the agent to globally install or upgrade a CLI before performing a simple airfare comparison task, which introduces unnecessary supply-chain and host-modification risk. Because this changes the execution environment and trusts a remote package source, a compromise of the package, dependency chain, or install path could lead to code execution beyond the skill's stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow normalizes disabling TLS verification for operational use and gives no warning about the resulting loss of transport authenticity. Even if intended as a workaround, this creates an unsafe default that can hide active interception and manipulated responses from the flight-search backend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The name, description, and operating instructions are entirely in Chinese and the trigger phrases are Chinese-only, but the file does not state that the skill is region-specific or that users may choose another language. This creates a natural-language locale restriction without opt-in, which matches the policy-violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes price-matrix comparison, but the body claims persistent self-learning and user-profile storage behavior. This is a scope mismatch that can mislead users and reviewers about retention, profiling, and stateful behavior, especially because persistence is privacy-relevant and not necessary for one-off fare comparison.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill reads persisted user profile data at startup without clearly warning in the main skill description that it will access privacy-sensitive stored information. Startup access without prominent disclosure undermines informed consent and may surprise users who expect an on-demand comparison tool rather than a profiling system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill falls back to reading a local file ~/.flyai/user-profile.md to obtain user profile data, which is not justified by the narrow purpose of multi-airport fare comparison. Local file access introduces privacy and boundary risks because it can expose persisted personal information outside the minimum data needed for the current request.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a multi-airport flight price comparison tool, but it expands into hotel and attraction booking link generation. This widens the skill’s operational scope beyond user expectations, increasing the chance of unintended data use, misleading activation, and unnecessary tool access for functions not required to compare flights.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs persistent memory updates for newly discovered preferences, which is broader than needed for airport price comparison and can lead to silent accumulation of personal travel habits. Unnecessary persistence raises privacy risk and creates opportunities for over-collection unrelated to the immediate task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation is written in Chinese and presents all user-facing prompts in Chinese, with no indication that language selection is optional or that the skill is intended only for Chinese-speaking users. Under the policy rule for natural-language violations, this creates a language/locale constraint without user opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The reference file exposes a generic AI travel search interface that supports hotels, attractions, flights, trains, and mixed travel planning, which is materially broader than the skill’s declared purpose of multi-airport flight price comparison. This scope mismatch can enable capability drift or prompt routing into unintended domains, increasing the chance that the agent performs actions or returns results outside the user-approved and policy-reviewed skill boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire example is written as a fixed Chinese-language interaction and output format, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented search supports many unrelated travel categories such as visas, hotels, dining, telecom, and cruises, giving the skill a much broader operational surface than its stated multi-airport pricing use case. In an agent setting, this creates tool-scope drift that can be abused for unintended actions or data retrieval, reducing predictability and weakening least-privilege design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The parameter documentation requires specific Chinese-language values such as 酒店, 民宿, 客栈, 大床房, 双床房, and 多床房. This imposes a locale/language constraint in the skill interface without stating that Chinese input is required, offering alternatives, or explaining why the constraint is necessary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly states that the skill should remember user parameters, learn preference patterns, and accumulate past cases, which goes beyond the stated airport price-comparison function. This creates a real risk of unauthorized persistence and profiling of user data, especially because no retention limits, consent flow, or scope restrictions are described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown describes retaining user parameters and learning preferences but provides no notice about privacy, storage, sharing, retention, or deletion. In a travel-price comparison skill, this omission is significant because users may disclose location, budget, and travel habits that can be profiled over time.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation says it will proactively provide information and predict the user's next needs, which is not part of the declared skill scope. That implies behavioral profiling and unsolicited actions based on inferred preferences, increasing privacy and trust risks if users did not expect such monitoring or recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document promotes proactive predictions and recommendations without warning that user behavior may be profiled to drive those suggestions. Even in a benign travel assistant, undisclosed profiling can erode user trust and create privacy risk by inferring travel intent, routines, or preferences from prior interactions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill documentation is written in Chinese and presents all user-facing examples and instructions exclusively in that language, with no indication that users can choose another language or that the skill is restricted to a Chinese-speaking context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The documentation instructs use of npx ...@latest, which fetches and executes the newest package version at runtime rather than a reviewed, pinned release. This creates a supply-chain risk: a compromised upstream package, malicious dependency update, or breaking release could execute arbitrary code in the agent environment when the skill is used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as a multi-airport airfare comparison tool, but the tool documentation exposes hotel, attractions, and restaurant search capabilities outside that scope. Excess capability increases attack surface and raises the chance of unintended tool use, prompt abuse, or data access beyond what users reasonably expect from this skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

对于一个旨在比较同城不同机场出发机票价格并计算综合交通成本的技能,访问酒店、景点和餐厅数据不是直接且明显的需求。将这些能力纳入技能可执行范围,会引入与声明场景无关的广泛旅行查询能力。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document defines persistent storage of broad user travel-profile data across platforms, including long-term preferences and history, which exceeds the narrow need of a multi-airport price comparison skill. This creates unnecessary retention of personal data and expands the privacy and misuse risk surface if the data is later accessed, correlated, or leaked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.