Back to skill

Security audit

帮我说服 TA

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent travel proposal helper, but it documents unsafe installation and network practices that users should review before installing.

Review this skill carefully before installing. Avoid running the documented sudo or global @latest npm install without independently verifying the FlyAI package identity and version, and do not disable TLS certificate validation for normal travel searches. If you use the profile feature, only save information you are comfortable keeping across sessions and know where it will be stored.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:129
Finding

Execution of Mutable and Inconsistently Identified npm Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:129-145; secondary conflicting dependency reference at reference/tools.md:28
Vulnerability Type: Supply-chain compromise through mutable package installation
Risk Level: High

Vulnerable Code

From SKILL.md:

bash
npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org
bash
flyai --help
bash
sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org

From reference/tools.md:

bash
npx @anthropic-ai/flyai-cli@latest

Technical Analysis

The Skill installs or executes an npm package using the mutable @latest tag. No exact version, lockfile, integrity hash, signature, or package-provenance check is required. As a result, the code executed at runtime can differ from the package that existed when the Skill was audited.

The documented package identity is also inconsistent:

  • SKILL.md installs @fly-ai/flyai-cli.
  • reference/tools.md executes @anthropic-ai/flyai-cli.

This inconsistency increases the chance of dependency confusion, package impersonation, or accidental execution of an unrelated package. npm installation may execute package lifecycle scripts, while npx downloads and runs package code directly.

Attack Path

  1. An attacker compromises one of the referenced npm packages, its publisher account, or the associated namespace.
  2. The attacker publishes a malicious release and causes it to resolve through the latest tag.
  3. The Agent follows the Skill instructions and runs npm install or npx.
  4. npm downloads the mutable package without an integrity policy tied to a reviewed artifact.
  5. Malicious lifecycle scripts or CLI entry points execute on the local host.
  6. If the privileged fallback is used, the malicious code executes with root permissions.

Impact Assessment

Successful exploitation can provide arbitrary code e ...[truncated 448 chars]

Remediation
View remediation

Remediation Suggestions

  1. Establish and document a single verified official package identity.
  2. Pin the dependency to an exact audited version rather than @latest.
  3. Use a project-local dependency and commit a lockfile with package integrity metadata.
  4. Verify package provenance, publisher identity, signatures, and registry integrity before execution.
  5. Avoid automatic package installation during every Skill invocation.
  6. Replace npx @package@latest with a locally installed, pinned executable.
  7. Disable or explicitly review npm lifecycle scripts where feasible.
  8. Remove the privileged installation fallback and run the package under a restricted, non-administrative account.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:154
Finding

Global Disabling of TLS Certificate Verification for Travel Queries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:154-170,243; repeated throughout reference/flyai-commands.md:1-159
Vulnerability Type: Insecure transport configuration
Risk Level: High

Vulnerable Code

From SKILL.md:

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight \
  --origin "[departure city]" --destination "[destination]" \
  --dep-date [departure date] --back-date [return date] --sort-type 3
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel \
  --dest-name "[destination]" --check-in-date [check-in date] \
  --check-out-date [check-out date] --sort price_asc
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi --city-name "[destination]"

The same environment setting is mandated for flight, hotel, attraction, and general keyword searches in reference/flyai-commands.md.

Technical Analysis

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 disables TLS certificate validation for HTTPS connections created by the Node.js process. The client can no longer reliably authenticate the remote server.

This is not a safe solution to a certificate error. It permits an endpoint using an expired, self-signed, incorrectly issued, or attacker-controlled certificate to be accepted. Because the setting applies to the entire CLI process, it may affect every HTTPS request made by the CLI and its dependencies, not only the intended FlyAI endpoint.

The affected requests contain travel plans and return data used to generate recommendations, prices, and links. An attacker able to intercept network traffic could therefore alter both requests and responses.

Attack Path

  1. The Agent launches the FlyAI CLI with certificate verification disabled.
  2. An attacker gains a network interception position, controls a local proxy, manipulates DNS, or operates a hostile access point.
  3. The attacker presents an arbitrary TLS certificate and impersonates the expected API server.

...[truncated 921 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove NODE_TLS_REJECT_UNAUTHORIZED=0 from every command.
  2. Correct the remote service's certificate chain and hostname configuration.
  3. Use the operating system trust store or a narrowly scoped, explicitly managed certificate authority.
  4. If certificate pinning is appropriate, pin the expected public key or certificate using a maintained rotation process.
  5. Fail closed when certificate verification fails; do not silently downgrade transport security.
  6. Display a clear error and require infrastructure remediation instead of advising users to bypass TLS.
  7. Add tests confirming that invalid, expired, mismatched, and self-signed certificates are rejected.
  8. Validate returned URLs and structured response fields before using them in generated proposals.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:143
Finding

Privileged Global Package Installation Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:143-145
Vulnerability Type: Unnecessary elevation of third-party package installation
Risk Level: High

Vulnerable Code

bash
sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org

Technical Analysis

The Skill recommends using sudo when global npm installation encounters a permission error. Travel search does not legitimately require root access. Elevating an npm installation is particularly dangerous because npm packages can execute lifecycle scripts during installation.

The command combines administrative privileges, global installation, and a mutable dependency version. This breaks the principle of least privilege and converts a package-registry or publisher compromise into a potential root-level compromise.

Attack Path

  1. A package installation fails because the global npm directory is not writable.
  2. The user follows the Skill's documented fallback and reruns the command with sudo.
  3. npm retrieves the package version currently associated with latest.
  4. A malicious package lifecycle script executes as root.
  5. The script modifies protected files, accesses root-readable data, creates privileged accounts, or installs persistent services.

Impact Assessment

Exploitation may grant full administrative control of the host. Root-level package code can read or alter any local file, access credentials and configuration belonging to other users, replace trusted executables, disable security tooling, modify network settings, and establish cross-session persistence. The scope is the entire host rather than only the Agent's workspace.

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions recommending sudo for npm installation.
  2. Install the CLI as a project-local dependency under an unprivileged account.
  3. Use a user-owned Node.js environment managed by a version manager when necessary.
  4. Pin and verify the exact package version before installation.
  5. Run the CLI in a sandbox or container with minimal filesystem and network permissions.
  6. Ensure the runtime account cannot write to protected system paths.
  7. If administrative deployment is genuinely required, use a separately reviewed deployment process rather than elevating commands during Skill execution.

other

Warning
Location
reference/user-profile-storage.md:36
Finding

Persistent Storage of Personal Travel and Household Profile Data Without Adequate Protection

Content
View full analysis

Vulnerability Details

File Location: reference/user-profile-storage.md:36-120,142-165; referenced by SKILL.md:21-37,266-268
Vulnerability Type: Excessive personal data persistence in memory or a predictable plaintext file
Risk Level: Medium

Vulnerable Code

Memory-based storage is invoked through the following operations:

python
search_memory(
    query="user travel profile",
    category="user_hobby",
    keywords="flyai",
    depth="shallow"
)
python
update_memory(
    action="create",
    category="user_hobby",
    title="user travel profile",
    keywords="travel preferences,user profile,flyai",
    content="- Home city: Hangzhou\n- Budget preference: Medium"
)

The local fallback uses a predictable profile location:

text
~/.flyai/user-profile.md
bash
mkdir -p ~/.flyai
cat ~/.flyai/user-profile.md
text
read_file(file_path="~/.flyai/user-profile.md")

The documented schema includes home city, preferred airport, budget, usual number of travelers, family characteristics, accommodation preferences, visited cities, and special requirements.

Technical Analysis

The Skill persistently records a personal travel profile either in Agent memory or in a plaintext Markdown file under the user's home directory. Although the documented write flow asks for user confirmation, the design does not specify:

  • Restrictive file permissions
  • Encryption at rest
  • A retention period
  • Automatic expiration
  • A deletion or export mechanism
  • Field-level sensitivity controls
  • Limits on collection of family and accessibility information

The predictable file path also makes the profile easy for other local processes running under the same account to locate. Automatic startup reads can expose stored information to later Agent sessions beyond the context in which it was originally supplied.

Attack Path

  1. During a travel- ...[truncated 1047 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make profile persistence explicitly opt-in and disabled by default.
  2. Explain exactly which fields will be stored, where they will be stored, and how long they will remain.
  3. Minimize collection to fields required for the current task; avoid persisting family and accessibility details unless specifically necessary.
  4. Create local files with permissions restricted to the owning user, such as mode 0600, and protect the containing directory appropriately.
  5. Encrypt sensitive profile data at rest using an operating-system credential store or another approved secret-storage mechanism.
  6. Implement profile review, correction, export, and deletion controls.
  7. Define retention periods and automatically remove stale records.
  8. Require renewed consent before reusing sensitive fields in a materially different context.
  9. Avoid placing sensitive values in searchable memory keywords or titles.
  10. Document whether memory content is synchronized externally and obtain separate consent if remote synchronization occurs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (50)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The commands explicitly set NODE_TLS_REJECT_UNAUTHORIZED=0, disabling TLS certificate validation for network requests. This makes the data retrieval path vulnerable to man-in-the-middle interception or tampering, allowing an attacker to alter returned travel data or deliver malicious responses while appearing trusted.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill normalizes disabling TLS verification for routine network operations without a strong warning, making insecure transport the documented default. Because the skill depends on 'real data' from remote services, tampered responses could directly affect generated advice and erode trust while exposing users to manipulated content.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation instructs users to bypass SSL/TLS verification without any risk warning or narrow scoping, normalizing an unsafe practice as mandatory. If followed, users may unknowingly accept spoofed servers and manipulated results, which is especially risky because the skill claims to provide 'real' pricing data to persuade others.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L003 中的触发词如“帮我说服”“怎么说服”都属于高频日常表达,且未限定必须与旅行规划相关,容易与普通对话场景重叠。描述里虽然说明是旅行提案生成器,但没有给出排除条件或更严格的触发范围,仍存在误触发风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that it will read and persist user profile data such as departure city, companions, and budget preferences, but does not provide clear privacy notice, retention limits, or consent flow. In context, this creates privacy and data-governance risk because travel preferences are personal data and the skill is designed to accumulate them over time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users/agents to globally install or upgrade a CLI via npm as a prerequisite, which expands system modification well beyond what a travel proposal skill minimally needs. Global package installation increases supply-chain and host-integrity risk, especially when paired with automatic upgrade-to-latest behavior that reduces version pinning and review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document tells users to perform global installation and even suggests sudo for permission issues, yet does not clearly warn about system-wide modification and elevated-privilege risk. In a non-admin travel skill, encouraging privileged installation without prominent safety guidance increases the chance of harmful or unnecessary host changes.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

Recommending sudo npm install -g causes package installation with elevated privileges, which can lead to full system compromise if the package, dependency chain, or install scripts are malicious or tampered with. This is disproportionate to the needs of a travel itinerary skill and increases host-level risk substantially.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |

**注意:** 此步骤只在首次使用时执行,后续调用会直接跳过已安装的情况。

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Using NODE_TLS_REJECT_UNAUTHORIZED=0 as an example/default for flight searches disables server certificate validation and makes the connection vulnerable to interception and response tampering. Because the returned pricing data drives downstream persuasive content, an attacker could manipulate recommendations or inject misleading information.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

1.1 搜索机票

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight \
  --origin "[出发城市]" --destination "[目的地]" \
  --dep-date [出发日期] --back-date [返回日期] --sort-type 3

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

The hotel search command uses an unsafe TLS default that disables certificate checks, allowing man-in-the-middle attacks against the remote query. This undermines the integrity of price and availability data and could be abused to feed false or maliciously altered results into the skill output.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

1.2 搜索酒店

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel \
  --dest-name "[目的地]" --check-in-date [入住日期] \
  --check-out-date [退房日期] --sort price_asc

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

The POI search command also disables TLS certificate verification, creating the same opportunity for network interception and tampering. In context, this is especially concerning because the skill presents retrieved destination information as trustworthy evidence for persuasion.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

1.3 搜索景点

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi --city-name "[目的地]"

阶段2: 顾虑分析 (Analysis)

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

The exception-handling guidance explicitly tells operators to solve SSL certificate failures by disabling certificate verification, institutionalizing an unsafe fallback. This turns a transient connectivity problem into a systemic security weakness that makes all subsequent remote data fetches vulnerable to interception.

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
| 说服失败 | 不催促,保存方案供后续查看 |
| 信息有误 | 所有数据标注来源和时间,"以上价格基于今日搜索结果" |
| 目的地信息不足 | 用 keyword-search 补充信息 |
| SSL 证书失败 | 确保命令前加 `NODE_TLS_REJECT_UNAUTHORIZED=0` |

---

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document explicitly requires all FlyAI commands to run with NODE_TLS_REJECT_UNAUTHORIZED=0, which disables TLS certificate validation for outbound HTTPS connections. This makes man-in-the-middle interception and tampering of travel search responses possible, undermining integrity and confidentiality even though the skill’s purpose is only travel proposal generation.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

This line sets an unsafe default by making TLS verification bypass a global prerequisite for every command in the reference. Because it is presented as a standard operating instruction, it increases the chance that insecure transport becomes entrenched in normal usage and exposes all queries and responses to interception or modification.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 3)May include surrounding context.

md
# FlyAI 命令参考

> ⚠️ **重要**:所有命令需加 `NODE_TLS_REJECT_UNAUTHORIZED=0` 前缀绕过 SSL 验证

## search-flight — 搜索机票

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This example repeats the insecure TLS-bypass pattern in a copy-paste-ready command, making users likely to execute it as written. Even if the command only searches flights, an attacker on the network could tamper with returned prices or destinations and mislead downstream decisions.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 12)May include surrounding context.

基础用法

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight \
  --origin "上海" --destination "巴厘岛" \
  --dep-date 2026-04-15 --back-date 2026-04-20 \
  --sort-type 3

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This persuasion-oriented example encourages insecure transport while retrieving supposedly authoritative pricing data. That combination is dangerous because manipulated low-price results could be used to create deceptive recommendations that users then forward to others as factual.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 34)May include surrounding context.

bash
# 证明"其实机票没那么贵"
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight \
  --origin "上海" --destination "曼谷" \
  --dep-date 2026-05-01 --sort-type 3 --max-price 2000

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This hotel-search example embeds disabled TLS verification in standard usage instructions. Doing so exposes search parameters and returned hotel pricing to network tampering, weakening trust in the generated travel proposal.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 48)May include surrounding context.

基础用法

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel \
  --dest-name "巴厘岛" \
  --check-in-date 2026-04-15 --check-out-date 2026-04-18 \
  --sort price_asc

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This example uses insecure transport in a scenario explicitly intended to persuade someone that premium lodging is affordable. If responses are intercepted or altered, false price claims can be injected into the proposal while appearing to come from a 'real data' source.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 70)May include surrounding context.

bash
# 证明"泳池别墅也不贵"
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel \
  --dest-name "巴厘岛" --key-words "泳池别墅" \
  --check-in-date 2026-04-15 --check-out-date 2026-04-18 \
  --sort price_asc --max-price 800

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
96% confidence
Finding

This POI search example again normalizes disabled TLS verification for ordinary API use. Although POI data may seem lower sensitivity, manipulated results can still mislead users about destination suitability, safety, or itinerary quality.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 85)May include surrounding context.

基础用法

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi \
  --city-name "巴厘岛"

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This keyword-search example encourages insecure retrieval of broad travel information, making search content susceptible to interception and tampering. Because keyword searches may influence itinerary, budget, or safety claims, compromised responses can directly affect user decisions.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 115)May include surrounding context.

基础用法

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search \
  --query "巴厘岛5天4晚攻略"

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This example fetches visa-related information while disabling TLS verification, which can let an attacker alter compliance-critical travel guidance. Incorrect visa information could cause missed travel requirements, financial loss, or denied boarding.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 123)May include surrounding context.

bash
# 获取签证信息(回应"签证麻烦"顾虑)
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search \
  --query "巴厘岛签证 中国免签"

# 获取安全信息(回应"不安全"顾虑)

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This command searches safety and security information over a channel with certificate validation disabled. That is particularly risky because tampered safety results could falsely reassure users or exaggerate danger, directly influencing personal safety decisions.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 127)May include surrounding context.

--query "巴厘岛签证 中国免签"

获取安全信息(回应"不安全"顾虑)

NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search
--query "巴厘岛 安全 治安"

text

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This command-composition example propagates the insecure default into a recommended workflow. Repetition across the workflow increases the chance users adopt certificate bypass as a normal pattern and exposes each data retrieval step to tampering.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 139)May include surrounding context.

bash
# 1. 搜索低价机票
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight \
  --origin "上海" --destination "巴厘岛" \
  --dep-date 2026-08-14 --back-date 2026-08-18 \
  --sort-type 3

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

This hotel step in the combined workflow inherits the same unsafe transport default. Since the skill’s value proposition depends on credible real-world pricing, insecure transport undermines the integrity of the generated proposal.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 145)May include surrounding context.

md
--sort-type 3

# 2. 搜索经济型酒店
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel \
  --dest-name "巴厘岛" \
  --check-in-date 2026-08-14 --check-out-date 2026-08-18 \
  --sort price_asc

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
96% confidence
Finding

This POI step repeats the TLS-verification bypass in a suggested multi-step travel research flow. Even where data sensitivity is lower, the repeated insecure pattern broadens the attack surface and reinforces unsafe operational behavior.

Content

Scanner excerpt · reference/flyai-commands.md (reported line 151)May include surrounding context.

--sort price_asc

3. 搜索景点门票

NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi
--city-name "巴厘岛"

text

Static analysis

No suspicious patterns detected.