Back to skill

Security audit

历史价格参谋

Security checks for vulnerabilities and agentic risk

Overview

This travel price-advice skill is mostly coherent, but it documents unsafe setup and runtime practices that users should review before installing.

Use the Review bucket before installing. Do not run the documented sudo install, avoid unpinned @latest global installs unless independently trusted, and do not disable TLS certificate verification. Treat returned booking URLs as untrusted until their destination is visible and verified. Only enable saved travel profiles if you are comfortable storing personal travel preferences, family details, and history, and prefer scoped storage with clear deletion controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T08 · Insecure Dependencies

Error
Location
reference/workflow.md:3
Finding

Mandatory Installation of an Unpinned Global Dependency

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
reference/workflow.md:16
Finding

Privilege Escalation Through Root-Level Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:54
Finding

TLS Certificate Verification Bypass

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:62
Finding

Shell Command Injection Through User-Supplied Search Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
reference/user-profile-storage.md:63
Finding

Plaintext Persistence of Sensitive Travel Profile Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
reference/workflow.md:246
Finding

Unvalidated External Booking URLs Rendered as Trusted Actions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (27)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow instructs users to disable TLS certificate verification with NODE_TLS_REJECT_UNAUTHORIZED=0 when encountering SSL issues. This removes protection against man-in-the-middle attacks, allowing tampering with API responses or package/service communication and exposing any data sent through the CLI.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Telling users to bypass TLS validation without any warning normalizes an unsafe practice and makes insecure operation the documented fallback. In this skill, the command is presented as a routine fix, which increases the chance users execute sensitive travel searches over an unauthenticated channel.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use the skill when the user mentions phrases like “会不会降价”, “该买还是等”, “价格评估”, and “价格趋势”, which are generic expressions that can arise in ordinary conversation. The file does not provide exclusion conditions or narrower trigger constraints, so it is unclear when the skill should activate versus when a general travel assistant should respond.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions direct the skill to retain and reuse user history and preferences, including reading from local profile storage, which creates a natural-language pathway for unnecessary disclosure and persistence of personal travel data. Because the skill is for price advice, this retention is disproportionate and increases the chance that historical preferences are surfaced or reused inappropriately.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill reads persisted user profile data and falls back to a local file to personalize price advice, which exceeds the minimally necessary scope of a simple travel price-evaluation skill. This creates unnecessary privacy and data-retention risk because historical preferences may be accessed without an explicit, session-specific need or clear user notice/consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs itself to read persisted user profile data without a clear user-facing privacy warning or consent step in the main documentation. Hidden or poorly disclosed background access to stored personal preferences is dangerous because users may not expect their prior travel profile or local files to be consulted for a new request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill expands from one-time price advice into ongoing preference tracking, historical consultation retention, and proactive alerts, which are not required by the stated purpose. That broader behavioral profiling increases the amount of retained user data and creates opportunities for misuse, overcollection, or unexpected disclosure of travel interests over time.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Ongoing logging of user travel interests and proactive reuse of that history introduces a meaningful data-leakage risk, since past routes, hotels, budgets, and decision patterns may be exposed or inferred later. In the context of a travel advisory skill, such longitudinal profiling is not essential and materially increases privacy risk relative to the skill's core function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Proactive notifications based on tracked user interests imply ongoing monitoring and retention of travel preferences, but the skill does not present an explicit warning or consent mechanism. This is risky because users may be surveilled or profiled beyond the immediate interaction without understanding the duration or scope of that tracking.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented save flow writes user preferences to persistent memory or local files for a simple advisory skill, creating unnecessary long-term storage of potentially sensitive travel behavior. Local file persistence especially increases risk because stored preferences may outlive user expectations and be accessible outside the immediate advisory context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The referenced documentation describes a generic AI travel semantic search capability, while the skill metadata claims a narrower price-advisor function focused on buy/wait decisions. This mismatch can cause the agent or integrators to invoke broader search behavior than intended, increasing the chance of over-collection of user data, unintended tool usage, or responses outside the advertised security and privacy boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage examples require Chinese city names (e.g. 北京, 上海, 東京) and the output fields are shown in Chinese strings such as 周六, 直达, and 经济舱, but the document does not state that the skill is China-locale-specific or that users can choose another language/locale. This creates a natural-language locale policy concern because the skill appears to assume a fixed language experience without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents accepted bed-type values and all usage examples in Chinese, with no indication that the skill is China-specific or that other languages/locales are supported. This creates a natural-language locale constraint that appears mandatory rather than optional, which can violate language-choice policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill focused on advising whether to book flights or hotels now based on real-time prices and pricing trends. This file instead defines a train-search reference with route, seat class, transfer, and sorting parameters, which is a distinct booking/search capability rather than price-advisory logic for flights or hotels.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document expands a price-advisor skill into collecting and persisting broad travel-profile data such as city, airport, family details, budget, and preferences, which is not necessary for answering a one-off 'buy now or wait' question. This creates unnecessary long-term retention of personal data and increases privacy risk, especially because the profile can persist across sessions and platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The storage guidance normalizes writing personal travel-profile data to memory services and local files without an explicit privacy warning, data classification, or user-facing notice about the sensitivity of the information. Users and integrators may therefore persist personal data without understanding the exposure, retention, or sharing implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The local file instructions direct storing user profile data in ~/.flyai/user-profile.md without warning that this file may be readable by other local processes, backups, sync tools, or users depending on system configuration. Because the example includes personal details such as home city, family status, and travel history, local plaintext persistence meaningfully increases confidentiality risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Creating ~/.flyai and persisting a travel profile introduces session persistence, allowing personal information to survive beyond the immediate interaction. While persistence itself is not inherently malicious, in this context it increases privacy exposure because the retained data is broader than needed for a simple price-advice workflow.

Content

Scanner excerpt · reference/user-profile-storage.md (reported line 73)May include surrounding context.

如果 ~/.flyai/ 目录不存在,需要先创建:

bash
mkdir -p ~/.flyai

文件格式

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed fields include long-term personal and behavioral data, including family composition and historical destinations, that are unrelated to the core function of evaluating whether to book now or wait. Storing such data creates a richer user profile that can expose sensitive lifestyle patterns if accessed by other tools, users, or compromised local environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow instructions, prompts, and output templates all assume Chinese-language interaction, with no indication that the user can opt into another language. Per the policy criteria, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow mandates globally installing or upgrading a CLI from npm before performing the task, which expands the trust boundary to a third-party package and encourages code execution on the host. In an agent skill context, this is risky because users may run network-fetched code unnecessarily for a simple price-analysis workflow, and automatic upgrading to latest reduces reproducibility and reviewability.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The workflow suggests using sudo to globally install the CLI, which encourages running network-fetched package installation with elevated privileges. If the package, dependency chain, or installation path is compromised, the resulting impact on the host can be severe.

Content

Scanner excerpt · reference/workflow.md (reported line 20)May include surrounding context.

md
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |

**注意:** 此步骤只在首次使用时执行,后续调用会直接跳过已安装的情况。

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 creates an unsafe default that disables server certificate verification for the invoked Node.js process. This materially weakens transport security and can enable interception or modification of data and responses in transit.

Content

Scanner excerpt · reference/workflow.md (reported line 59)May include surrounding context.

重要:SSL 证书验证问题处理 如果遇到 "SSL 证书验证失败" 错误,需要在命令前加上环境变量:

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai <command>

2.1 机票价格搜索

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains only Chinese-language example queries, which can imply the skill is intended to be used in Chinese without any explicit user opt-in or documented locale limitation. The documented examples do not indicate that other languages are supported or that the language choice is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing example dialogue exclusively in Chinese, and there is no indication that the skill supports other languages or that Chinese-only behavior is an intentional, justified locale constraint. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.