T08 · Insecure Dependencies
- Location
reference/workflow.md:3- Finding
Mandatory Installation of an Unpinned Global Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This travel price-advice skill is mostly coherent, but it documents unsafe setup and runtime practices that users should review before installing.
Use the Review bucket before installing. Do not run the documented sudo install, avoid unpinned @latest global installs unless independently trusted, and do not disable TLS certificate verification. Treat returned booking URLs as untrusted until their destination is visible and verified. Only enable saved travel profiles if you are comfortable storing personal travel preferences, family details, and history, and prefer scoped storage with clear deletion controls.
reference/workflow.md:3Mandatory Installation of an Unpinned Global Dependency
reference/workflow.md:16Privilege Escalation Through Root-Level Package Installation
reference/workflow.md:54TLS Certificate Verification Bypass
reference/workflow.md:62Shell Command Injection Through User-Supplied Search Parameters
reference/user-profile-storage.md:63Plaintext Persistence of Sensitive Travel Profile Data
reference/workflow.md:246Unvalidated External Booking URLs Rendered as Trusted Actions
The workflow instructs users to disable TLS certificate verification with NODE_TLS_REJECT_UNAUTHORIZED=0 when encountering SSL issues. This removes protection against man-in-the-middle attacks, allowing tampering with API responses or package/service communication and exposing any data sent through the CLI.
Telling users to bypass TLS validation without any warning normalizes an unsafe practice and makes insecure operation the documented fallback. In this skill, the command is presented as a routine fix, which increases the chance users execute sensitive travel searches over an unauthenticated channel.
The description says to use the skill when the user mentions phrases like “会不会降价”, “该买还是等”, “价格评估”, and “价格趋势”, which are generic expressions that can arise in ordinary conversation. The file does not provide exclusion conditions or narrower trigger constraints, so it is unclear when the skill should activate versus when a general travel assistant should respond.
The instructions direct the skill to retain and reuse user history and preferences, including reading from local profile storage, which creates a natural-language pathway for unnecessary disclosure and persistence of personal travel data. Because the skill is for price advice, this retention is disproportionate and increases the chance that historical preferences are surfaced or reused inappropriately.
The skill reads persisted user profile data and falls back to a local file to personalize price advice, which exceeds the minimally necessary scope of a simple travel price-evaluation skill. This creates unnecessary privacy and data-retention risk because historical preferences may be accessed without an explicit, session-specific need or clear user notice/consent.
The skill instructs itself to read persisted user profile data without a clear user-facing privacy warning or consent step in the main documentation. Hidden or poorly disclosed background access to stored personal preferences is dangerous because users may not expect their prior travel profile or local files to be consulted for a new request.
The skill expands from one-time price advice into ongoing preference tracking, historical consultation retention, and proactive alerts, which are not required by the stated purpose. That broader behavioral profiling increases the amount of retained user data and creates opportunities for misuse, overcollection, or unexpected disclosure of travel interests over time.
Ongoing logging of user travel interests and proactive reuse of that history introduces a meaningful data-leakage risk, since past routes, hotels, budgets, and decision patterns may be exposed or inferred later. In the context of a travel advisory skill, such longitudinal profiling is not essential and materially increases privacy risk relative to the skill's core function.
Proactive notifications based on tracked user interests imply ongoing monitoring and retention of travel preferences, but the skill does not present an explicit warning or consent mechanism. This is risky because users may be surveilled or profiled beyond the immediate interaction without understanding the duration or scope of that tracking.
The documented save flow writes user preferences to persistent memory or local files for a simple advisory skill, creating unnecessary long-term storage of potentially sensitive travel behavior. Local file persistence especially increases risk because stored preferences may outlive user expectations and be accessible outside the immediate advisory context.
The referenced documentation describes a generic AI travel semantic search capability, while the skill metadata claims a narrower price-advisor function focused on buy/wait decisions. This mismatch can cause the agent or integrators to invoke broader search behavior than intended, increasing the chance of over-collection of user data, unintended tool usage, or responses outside the advertised security and privacy boundaries.
The usage examples require Chinese city names (e.g. 北京, 上海, 東京) and the output fields are shown in Chinese strings such as 周六, 直达, and 经济舱, but the document does not state that the skill is China-locale-specific or that users can choose another language/locale. This creates a natural-language locale policy concern because the skill appears to assume a fixed language experience without opt-in.
The file presents accepted bed-type values and all usage examples in Chinese, with no indication that the skill is China-specific or that other languages/locales are supported. This creates a natural-language locale constraint that appears mandatory rather than optional, which can violate language-choice policy.
The manifest describes a skill focused on advising whether to book flights or hotels now based on real-time prices and pricing trends. This file instead defines a train-search reference with route, seat class, transfer, and sorting parameters, which is a distinct booking/search capability rather than price-advisory logic for flights or hotels.
The document expands a price-advisor skill into collecting and persisting broad travel-profile data such as city, airport, family details, budget, and preferences, which is not necessary for answering a one-off 'buy now or wait' question. This creates unnecessary long-term retention of personal data and increases privacy risk, especially because the profile can persist across sessions and platforms.
The storage guidance normalizes writing personal travel-profile data to memory services and local files without an explicit privacy warning, data classification, or user-facing notice about the sensitivity of the information. Users and integrators may therefore persist personal data without understanding the exposure, retention, or sharing implications.
The local file instructions direct storing user profile data in ~/.flyai/user-profile.md without warning that this file may be readable by other local processes, backups, sync tools, or users depending on system configuration. Because the example includes personal details such as home city, family status, and travel history, local plaintext persistence meaningfully increases confidentiality risk.
Creating ~/.flyai and persisting a travel profile introduces session persistence, allowing personal information to survive beyond the immediate interaction. While persistence itself is not inherently malicious, in this context it increases privacy exposure because the retained data is broader than needed for a simple price-advice workflow.
如果 ~/.flyai/ 目录不存在,需要先创建:
mkdir -p ~/.flyai
The listed fields include long-term personal and behavioral data, including family composition and historical destinations, that are unrelated to the core function of evaluating whether to book now or wait. Storing such data creates a richer user profile that can expose sensitive lifestyle patterns if accessed by other tools, users, or compromised local environments.
The workflow instructions, prompts, and output templates all assume Chinese-language interaction, with no indication that the user can opt into another language. Per the policy criteria, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is documented and justified.
The workflow mandates globally installing or upgrading a CLI from npm before performing the task, which expands the trust boundary to a third-party package and encourages code execution on the host. In an agent skill context, this is risky because users may run network-fetched code unnecessarily for a simple price-analysis workflow, and automatic upgrading to latest reduces reproducibility and reviewability.
The workflow suggests using sudo to globally install the CLI, which encourages running network-fetched package installation with elevated privileges. If the package, dependency chain, or installation path is compromised, the resulting impact on the host can be severe.
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |
**注意:** 此步骤只在首次使用时执行,后续调用会直接跳过已安装的情况。
Setting NODE_TLS_REJECT_UNAUTHORIZED=0 creates an unsafe default that disables server certificate verification for the invoked Node.js process. This materially weakens transport security and can enable interception or modification of data and responses in transit.
重要:SSL 证书验证问题处理 如果遇到 "SSL 证书验证失败" 错误,需要在命令前加上环境变量:
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai <command>
2.1 机票价格搜索
This markdown file contains only Chinese-language example queries, which can imply the skill is intended to be used in Chinese without any explicit user opt-in or documented locale limitation. The documented examples do not indicate that other languages are supported or that the language choice is optional.
This markdown file contains user-facing example dialogue exclusively in Chinese, and there is no indication that the skill supports other languages or that Chinese-only behavior is an intentional, justified locale constraint. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
No suspicious patterns detected.