Back to skill

Security audit

旅行盲盒

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent travel-planning purpose, but it asks agents to use unsafe install, TLS, and persistent profile-storage practices that deserve review before use.

Review this skill before installing. Do not run its npm install, npx, or sudo commands unless the CLI package identity, version, and integrity are verified. Do not use commands with NODE_TLS_REJECT_UNAUTHORIZED=0. Only enable profile storage if you are comfortable persisting travel preferences and household details, and know how to inspect and delete the stored data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
reference/workflow.md:3
Finding

Mutable npm Package Is Retrieved and Installed Globally Before Searches

Content
View full analysis

Vulnerability Details

File Location: reference/workflow.md, lines 3-12; reference/tools.md, lines 24-30
Vulnerability Type: Unpinned remote dependency retrieval and execution
Risk Level: High

Evidence

markdown
### 前置步骤:安装/升级 FlyAI CLI

在执行任何搜索之前,**必须先执行安装命令**(无论是否已安装,确保为最新版本):

```bash
npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org

💡 此命令会自动处理首次安装和版本升级,无需手动判断是否已安装。安装后验证:

bash
flyai --help
text

A separate tool reference names a different package:

```markdown
## FlyAI 核心能力

使用 `npx @anthropic-ai/flyai-cli@latest` 调用飞猪数据。

**常用命令**:
- `search flights`: 搜索航班
- `search hotels`: 搜索酒店
- `search attractions`: 搜索景点
- `search restaurants`: 搜索餐厅

Technical Analysis

The workflow directs the agent to retrieve the mutable latest release of an npm package and install it globally before performing travel searches. npm installation can execute package lifecycle scripts, including preinstall, install, and postinstall. Consequently, the code executed at runtime is not the code that existed when this skill was audited.

No exact package version, integrity hash, lockfile, signature verification, or trusted publisher validation is specified. The documentation also inconsistently identifies the package as both @fly-ai/flyai-cli and @anthropic-ai/flyai-cli. This ambiguity increases the chance that an operator or agent retrieves an unintended package.

The use of global installation broadens the effect beyond the current project. It can replace a pre-existing flyai executable and affect subsequent sessions or unrelated projects.

Attack Path

  1. An attacker compromises the npm publisher account, package repository, release pipeline, or one of the named package scopes.
  2. The attacker publishes a malicious release that becomes the package's latest version.
  3. A user invokes the skill for an ordinary travel search.
  4. The workflow runs npm install -g ...@latest.
  5. npm downloads t ...[truncated 1104 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic installation or upgrading from the skill's normal execution path.
  2. Require the CLI to be installed through a separate, explicit administrator-controlled setup process.
  3. Select one verified package identity and use it consistently throughout all documentation.
  4. Pin an exact reviewed version, for example @fly-ai/flyai-cli@1.2.3, rather than @latest.
  5. Verify package integrity against an independently published SHA-256 digest, signed provenance, or trusted package-lock entry.
  6. Disable npm lifecycle scripts during installation where the package supports operation without them:
    bash
    npm install --ignore-scripts --save-exact @fly-ai/flyai-cli@1.2.3
    
  7. Prefer a project-local dependency over a global installation and invoke it through a fixed local path.
  8. Do not use npx ...@latest, because it retains the same mutable remote-execution risk.
  9. Document the expected publisher, repository, package digest, executable path, and release verification procedure.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
reference/workflow.md:18
Finding

Workflow Recommends Privileged Global Installation Through sudo

Content
View full analysis

Vulnerability Details

File Location: reference/workflow.md, lines 18-21
Vulnerability Type: Unnecessary privilege escalation for dependency installation
Risk Level: High

Evidence

markdown
**安装失败处理:**
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |

Technical Analysis

When an unprivileged global npm installation fails, the workflow recommends rerunning it through sudo. This grants root privileges to npm itself, the downloaded package, its transitive dependencies, and all package lifecycle scripts.

A travel-search utility does not legitimately require administrator access. Combining sudo with an unpinned remote package violates least privilege and changes a package compromise from user-level code execution into potential system-level compromise.

The recommendation also permits a remote package to write into system-wide npm directories and replace globally available binaries. Depending on npm configuration and lifecycle scripts, malicious code can modify other privileged locations as root.

Attack Path

  1. An attacker publishes or injects a malicious version into the package or its dependency chain.
  2. The ordinary global installation fails due to permissions.
  3. Following the skill's prescribed recovery procedure, the user runs the command with sudo.
  4. npm downloads the mutable latest package.
  5. A malicious lifecycle script executes as root.
  6. The script modifies system files, installs a privileged executable, replaces global tools, or creates another persistence mechanism.

An attacker does not need to exploit an operating-system vulnerability; the workflow explicitly asks the user to grant the required privilege.

Impact Assessment

The package and its installation scripts ...[truncated 318 chars]

Remediation
View remediation

Remediation Suggestions

  1. Delete the sudo npm install -g recommendation.
  2. Never grant administrator privileges to package installation initiated by a conversational skill.
  3. Use a project-local, exactly pinned dependency under an unprivileged account.
  4. If a global CLI is unavoidable, require a separate administrator-reviewed installation procedure with version and integrity verification.
  5. Recommend a user-owned Node.js installation through a version manager without presenting sudo as an equivalent fallback.
  6. Run the CLI in a sandbox with minimal filesystem and network permissions.
  7. Refuse execution if the verified CLI is unavailable rather than dynamically escalating privileges.

T09 · Insecure Skill Coding Practices

Error
Location
reference/workflow.md:106
Finding

TLS Certificate Validation Is Explicitly Disabled for Travel Searches

Content
View full analysis

Vulnerability Details

File Location: reference/workflow.md, lines 106-122
Vulnerability Type: Disabled TLS certificate verification
Risk Level: High

Evidence

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai keyword-search \
  --query "[出发城市]出发 飞行[X小时]内 [天数]天 人均[预算]以内"
bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight \
  --origin "[出发城市]" --destination "[候选目的地]" \
  --dep-date [出发日期] --back-date [返回日期] \
  --sort-type 3 --journey-type 1

The same unsafe setting is used for subsequent hotel and attraction searches:

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-hotel \
  --dest-name "[抽中城市]" \
  --check-in-date [入住日期] --check-out-date [退房日期] \
  --max-price [预算/晚数/60%] --sort rate_desc

NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-poi --city-name "[抽中城市]"

The primary skill definition also prescribes this behavior:

markdown
| SSL 证书验证失败 | 确保命令前加 `NODE_TLS_REJECT_UNAUTHORIZED=0` |

Technical Analysis

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 disables certificate verification for TLS connections made by the Node.js process. Encryption without peer authentication does not establish that the client is communicating with the intended travel service.

A network-positioned attacker can present an arbitrary certificate and intercept or modify requests and responses. The commands expose user-derived travel information such as departure location, dates, destination candidates, budget, and trip duration. Altered responses may contain manipulated prices, flight details, hotel details, or destination links.

Because the setting is scoped to the entire flyai process, it affects every TLS request made by that process, not merely the connection that originally produced a certificate error.

Attack Path

  1. The user invokes the skill on an untrusted or attacker-controlled network.
  2. The skill starts the CLI with NODE_TLS_REJECT_UNAUTHORIZED=0.
  3. An attacker intercepts DNS or network traffic and presents a fraudu ...[truncated 970 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove every use of NODE_TLS_REJECT_UNAUTHORIZED=0.
  2. Treat certificate-validation failure as a hard error rather than a condition to bypass.
  3. Correct the system trust store, server certificate chain, hostname, proxy configuration, and system clock.
  4. If a private certificate authority is required, configure a narrowly scoped CA bundle, such as through NODE_EXTRA_CA_CERTS, after verifying its fingerprint.
  5. Avoid process-wide TLS overrides.
  6. Validate returned booking URLs against an allowlist of expected HTTPS domains before presenting them as actionable links.
  7. Minimize personal information included in remote search queries and inform users what itinerary data is sent to the service.
  8. Add tests that fail when TLS verification is disabled or when an untrusted certificate is accepted.

T09 · Insecure Skill Coding Practices

Warning
Location
reference/user-profile-storage.md:66
Finding

Sensitive Travel Profile Is Stored in Plaintext Without Access-Control or Deletion Requirements

Content
View full analysis

Vulnerability Details

File Location: reference/user-profile-storage.md, lines 66-110
Vulnerability Type: Insecure local storage of personal profile data
Risk Level: Medium

Evidence

markdown
## 模式 B:本地文件

### 文件路径

~/.flyai/user-profile.md

text

如果 `~/.flyai/` 目录不存在,需要先创建:
```bash
mkdir -p ~/.flyai

文件格式

markdown
# FlyAI 用户旅行画像

> 最后更新: 2026-04-03 15:30

## 基础信息
- 常驻城市: 杭州
- 出发机场: 萧山机场

## 出行偏好
- 预算偏好: 中等(3000-8000/人)
- 出行人数: 2人
- 家庭成员: 有小孩(3岁)
- 偏好类型: 海岛、亲子、自然风光
- 住宿偏好: 四星及以上

## 历史记录
- 去过城市: 三亚、厦门、大理

## 特殊需求
- 宠物友好: 否
- 无障碍: 否

读取文件

bash
cat ~/.flyai/user-profile.md

或使用工具:

text
read_file(file_path="~/.flyai/user-profile.md")
text

### Technical Analysis

The fallback profile is a plaintext Markdown file containing persistent personal information, including residence, preferred airport, budget, usual party size, the existence and age of a child, travel history, lodging preferences, and accessibility needs.

The setup command only creates the directory with `mkdir -p`; it does not require restrictive permissions. File creation similarly has no prescribed mode, ownership check, atomic-write procedure, symlink defense, encryption, retention limit, or secure-deletion mechanism. Actual exposure depends on the user's umask and existing filesystem permissions, but the specification does not establish a safe baseline.

The skill does request confirmation before saving newly detected preferences, which reduces unauthorized writes. However, startup reads are automatic, and no documented mechanism lets the user inspect, expire, selectively remove, or completely delete the stored profile.

### Attack Path

1. The user approves profile storage, causing the agent to create or update `~/.flyai/user-profile.md`.
2. The file is created according to ambient directory permissions and umask rather than an enforced restrictive mode.
3. Another local process, compromised application, backup collector, or same-host user wit
...[truncated 1068 chars]
Remediation
View remediation

Remediation Suggestions

  1. Apply data minimization. Do not persist child age, accessibility information, exact residence, travel history, or other sensitive fields unless strictly necessary and separately approved.
  2. Create the directory and file with restrictive permissions:
    bash
    install -d -m 700 "$HOME/.flyai"
    install -m 600 /dev/null "$HOME/.flyai/user-profile.md"
    
  3. Verify that the directory and file are owned by the current user and are not symbolic links before every read or write.
  4. Use atomic writes through a securely created temporary file in the same protected directory, followed by an atomic rename.
  5. Encrypt sensitive profile fields at rest using an operating-system credential store or a user-controlled key.
  6. Present exactly which fields will be saved and obtain granular opt-in consent.
  7. Add commands to view, edit, selectively remove, expire, and completely delete the profile.
  8. Define a short retention period and avoid indefinite storage of travel history.
  9. For remote memory providers, disclose where data is stored and obtain separate consent before uploading it.
  10. Do not automatically read persistent profile data when the user requests a fresh or memory-free session.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (38)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented fallback to read a local file (~/.flyai/user-profile.md) introduces access to host-local data that is not necessary for core travel blindbox functionality. Local file access can expose unrelated personal information, bypass centralized memory controls, and creates a larger attack surface if the file contains sensitive or unexpected content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs persistent saving of preferences to memory or local files, which exceeds the narrow purpose of generating a random travel destination and can create long-term personal data accumulation. Storing user preferences and travel history in local files especially raises privacy and unauthorized access risks if the environment is shared or insufficiently isolated.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Disabling TLS verification for keyword and flight searches is an unsafe operational instruction with direct security consequences. It normalizes insecure transport settings and permits interception or manipulation of remote responses without any warning to the operator.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow explicitly sets NODE_TLS_REJECT_UNAUTHORIZED=0 for network searches, which disables TLS certificate validation. This makes all FlyAI CLI requests vulnerable to man-in-the-middle interception or tampering, allowing an attacker to alter flight, hotel, or destination data or capture sensitive query information.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The same TLS-bypass pattern is repeated for hotel and POI lookups, extending insecure communication across the remainder of the workflow. Because these are live network-dependent steps, an attacker on path could tamper with prices, lodging, or itinerary data and mislead downstream decisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L03 列出的触发语中包含“选择困难”“不知道去哪”“盲盒”等高频日常表达,且与普通聊天场景高度重叠,容易在非旅行盲盒意图下也触发该技能。描述虽给出若干示例短语,但没有限定上下文、排除条件或负例,触发边界仍然不清晰。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill expands from a simple travel destination randomizer into a persistent profiling system that '自主学习' and stores long-term user travel history and preferences. That materially broadens data collection and retention beyond what users would reasonably expect from a blindbox travel helper, increasing privacy risk and the chance of unintended cross-session profiling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes reading stored user profile data and falling back to local files, but does not clearly disclose persistence scope, retention, or privacy implications before use. That lack of transparency undermines meaningful consent and makes covert accumulation or reuse of personal travel data more dangerous in this context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation tells the agent to update memory when users mention preferences or visited cities, but does not provide a clear risk notice or consent flow for long-term storage. This creates a privacy vulnerability because sensitive behavioral data can be silently persisted across sessions under a seemingly lightweight travel feature.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

The instruction to set NODE_TLS_REJECT_UNAUTHORIZED=0 disables TLS certificate validation, enabling man-in-the-middle interception or tampering of network traffic to travel services. In a skill that may query flights, hotels, and POIs and handle user preferences, this can expose sensitive requests and allow attackers to alter results or harvest data.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
| 候选池太少(不足3个) | 提示"条件较严格,只找到X个目的地,建议放宽预算或飞行时间" |
| 候选池为空 | 诚实告知,建议调整条件,给出具体调整建议 |
| 3次重抽都不满意 | 展示完整候选列表让用户自选 |
| SSL 证书验证失败 | 确保命令前加 `NODE_TLS_REJECT_UNAUTHORIZED=0` |
| 价格波动导致超预算 | 标注"按当前价格计算,建议尽快预订锁价" |
| 搜索返回空结果 | 调整搜索条件,或用 AI 通识知识推荐替代目的地 |
| 用户去过的城市无记录 | 询问用户"有没有已经去过不想再去的城市?" |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reference documentation exposes a broad, general-purpose AI travel search capability that goes beyond the skill’s declared purpose of random-travel blindbox destination selection. This creates scope expansion risk: an agent may invoke or rely on undocumented broader search behavior, leading to unintended data access, policy bypass, or use of the skill for travel planning tasks outside its approved boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire markdown content is written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, a language-specific constraint without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example presents specific flight and hotel prices and then prompts the user to proceed with booking without any disclaimer that fares, room rates, and availability are dynamic and must be rechecked before reservation. In a travel-booking context, this can mislead users into relying on stale or illustrative pricing, causing financial harm, failed bookings, or disputes when the real cost differs materially.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation claims long-term memory, preference learning, and accumulation of successful cases, which materially expands the skill beyond a simple random-destination assistant. This creates security and privacy risk because operators or downstream components may implement persistent profiling and data retention without explicit scope, consent, or controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The text explicitly says the skill remembers user parameters and learns preference patterns, but provides no warning about retention, privacy impact, or user control. In a travel context, retained origin city, budget, and preference data can reveal behavioral patterns and create unnecessary profiling risk if stored long term.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation states that failure cases will be collected for analysis, implying retention of interaction data without informing users. These records may include travel constraints, excluded cities, timing, or other preference signals that can expose personal habits if logged unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill documentation is written in Chinese and does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. This creates a natural-language policy concern because it effectively imposes a specific language/locale without user choice or justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The documentation instructs use of npx @anthropic-ai/flyai-cli@latest, which fetches and executes the newest package version at runtime rather than a pinned, reviewed release. If the package is compromised or a breaking/malicious update is published, users of the skill could execute untrusted code in their environment, making this a real supply-chain risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document defines cross-platform, persistent user-profile storage that goes beyond the skill's stated purpose of randomly selecting travel destinations under user-supplied constraints. This creates unnecessary data retention and expands the privacy attack surface by storing travel preferences, home city, family details, and history across sessions without a strong functional need demonstrated in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The specification describes writing personal travel-profile data to Qoder Memory or a local file but does not warn about persistence, local exposure, or privacy implications. Users or downstream skill authors may treat the behavior as routine, leading to silent retention of personal data such as residence, child status, and travel history on disk or in shared memory systems.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The file instructs creation and use of a persistent local directory under ~/.flyai for storing a user profile, which introduces session persistence of personal data on the host system. In the context of a lightweight travel recommendation skill, this is more dangerous because it creates durable local artifacts containing personal and family-related travel information without specifying safeguards such as access controls, encryption, or retention periods.

Content

Scanner excerpt · reference/user-profile-storage.md (reported line 73)May include surrounding context.

如果 ~/.flyai/ 目录不存在,需要先创建:

bash
mkdir -p ~/.flyai

文件格式

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template instructs the skill to save newly discovered preferences into persistent storage, but the skill's declared function does not clearly require maintaining a long-term profile. Because the stored fields can include sensitive lifestyle and family information, persistent accumulation raises privacy risk and possible secondary use beyond the immediate blind-box travel recommendation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The workflow requires installing or upgrading a global CLI before any search, which introduces unnecessary system modification for a user-facing travel-selection skill. Forcing a global package install expands supply-chain and execution risk, especially because it pulls latest code from the registry and executes it on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to run a global npm install/upgrade, and even suggests sudo for permission issues, without adequately warning that this changes the system and may execute package lifecycle scripts with elevated privileges. This creates avoidable supply-chain and host-integrity risk beyond the travel use case itself.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

Suggesting sudo npm install -g runs package installation with root privileges, which is dangerous because npm packages may execute install scripts and modify privileged locations. In the context of an agent skill, this is especially risky because it encourages elevated execution for routine functionality.

Content

Scanner excerpt · reference/workflow.md (reported line 20)May include surrounding context.

md
| 情况 | 处理方式 |
|-----|---------|
| npm 未安装 | 提示用户先安装 Node.js (https://nodejs.org/) |
| 权限不足 | 建议使用 `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` 或使用 nvm 管理 Node |
| 网络问题 | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |

**注意:** 此步骤只在首次使用时执行,后续调用会直接跳过已安装的情况。

Static analysis

No suspicious patterns detected.