Back to skill

Security audit

行程体检

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate travel-checking purpose, but it asks for unsafe system changes, disables secure connection checks, and uses persistent personal travel profiles too broadly.

Install only after the publisher removes the TLS bypass, avoids global unpinned npm installation and sudo guidance, makes profile reads and writes explicit opt-in with deletion controls, and makes booking links optional with clear third-party disclosure and URL validation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:106
Finding

Mandatory Injection of Third-Party Commercial Booking Links

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:106-113; reinforced by reference/output-template.md:22-27, 75-78, 128-138, 151-163
Vulnerability Type: Mandatory commercial output manipulation
Risk Level: Medium

Code Snippet

markdown
### Step 6: Extract booking links

The `jumpUrl` field returned by FlyAI is a Fliggy booking link and must be displayed:

👉 [Book a flight now](https://a.feizhu.com/xxxxx)
👉 [View hotel details](https://a.feizhu.com/xxxxx)
👉 [Purchase attraction tickets](https://a.feizhu.com/xxxxx)

The required output template further inserts jumpUrl values into flight, hotel, and attraction recommendations and adds a dedicated quick-booking section.

Technical Analysis

The Skill does not merely permit relevant source links. It explicitly requires the Agent to place third-party Fliggy booking links into its answer. The prescribed output template repeats these links throughout an otherwise analytical itinerary report.

This alters the Agent's expected reporting behavior by introducing a mandatory commercial objective. Users asking for an itinerary assessment may therefore receive promotional links even when those links are not needed to answer the request. The Skill does not disclose whether the links are sponsored, affiliated, tracked, or selected independently.

The URLs originate from the output of a third-party CLI. The instructions do not require validation of the URL host, scheme, redirect destination, or integrity before the link is shown as a trusted booking action.

Attack Path

  1. A user activates the itinerary-checking Skill.
  2. The Agent invokes a FlyAI search command.
  3. FlyAI returns one or more jumpUrl values.
  4. The Skill requires the Agent to insert those values into the final report.
  5. The Agent presents the links as trusted booking actions.
  6. The user may follow a commercial or potentially manipulated redirect under the impression that it ...[truncated 466 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement that booking links must be displayed.
  2. Only provide booking links when the user explicitly asks for purchasing options.
  3. Clearly disclose commercial, affiliate, referral, or tracking relationships.
  4. Separate objective itinerary findings from commercial recommendations.
  5. Validate each returned URL before rendering it:
    • Require HTTPS.
    • Use an explicit hostname allowlist.
    • Reject embedded credentials and non-web schemes.
    • Resolve and inspect redirects where feasible.
  6. Label third-party data and links as untrusted external content.
  7. Offer noncommercial and official-provider alternatives where available.

T08 · Insecure Dependencies

Error
Location
SKILL.md:37
Finding

Unpinned Global npm Installation with Optional Root Elevation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:37-48
Vulnerability Type: Mutable supply-chain dependency installed globally, potentially with elevated privileges
Risk Level: High

Code Snippet

bash
npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org

The associated failure guidance instructs the Agent to use sudo or nvm when installation fails because of insufficient permissions. It also permits changing the npm registry when network problems occur.

Technical Analysis

The dependency is installed using the mutable latest tag. Consequently, the code executed during one Skill invocation may differ from the code reviewed during another invocation. No exact version, lockfile, integrity hash, signature, provenance requirement, or package-content review is provided.

npm packages can execute lifecycle scripts during installation. A compromised package publisher, npm account, dependency, registry response, or newly published release could therefore execute arbitrary code on the host.

The global -g installation expands the effect beyond a temporary project environment. Recommending sudo can additionally execute package installation and lifecycle scripts with root privileges. Repeating installation before searches also increases exposure to future package changes and supply-chain compromise.

Attack Path

  1. An attacker compromises the package, publisher account, transitive dependency, registry path, or a future release selected by latest.
  2. The user activates the Skill for an ordinary itinerary query.
  3. The Agent runs the mandatory global npm installation.
  4. npm downloads the attacker-controlled version and executes applicable lifecycle scripts.
  5. If normal installation reports a permission error, the documented recovery path may cause the command to be repeated with sudo.
  6. Malicious package code executes with the current user's privileges or, in the e ...[truncated 784 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed version rather than @latest.
  2. Verify package integrity with a lockfile and registry-provided integrity hashes.
  3. Require package provenance or signature verification where supported.
  4. Install the dependency locally in a dedicated, unprivileged, sandboxed environment.
  5. Never recommend sudo for npm package installation.
  6. Disable installation lifecycle scripts unless they are strictly required and audited.
  7. Do not reinstall or upgrade automatically on every search.
  8. Separate dependency installation from normal Skill execution and request explicit user approval.
  9. Restrict filesystem, process, credential, and network access available to the CLI.
  10. Audit both the direct package and its complete transitive dependency tree.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:79
Finding

Global TLS Certificate Verification Bypass

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:79; repeated in reference/scoring-rules.md:37
Vulnerability Type: Disabled HTTPS server authentication
Risk Level: High

Code Snippet

bash
NODE_TLS_REJECT_UNAUTHORIZED=0 flyai search-flight ...

The failure-handling rules prescribe the same environment variable whenever SSL certificate validation fails.

Technical Analysis

Setting NODE_TLS_REJECT_UNAUTHORIZED=0 disables TLS certificate verification for Node.js HTTPS requests made by the affected process. Encryption may still occur, but the client no longer reliably authenticates the remote server.

This converts a certificate failure, which should stop communication, into a connection that accepts untrusted certificates. An attacker able to intercept network traffic can impersonate the service, inspect submitted travel data, or modify responses.

Because the CLI returns prices and booking URLs that the Agent is instructed to trust and display, response manipulation can directly affect recommendations and user navigation. The workaround is documented in both the main workflow and failure-handling rules, demonstrating that it is intended behavior rather than an isolated example.

Attack Path

  1. The legitimate endpoint presents an invalid certificate, or an attacker causes certificate validation to fail.
  2. The Agent follows the documented workaround and launches the CLI with TLS verification disabled.
  3. A network-positioned attacker presents an arbitrary certificate and impersonates the expected service.
  4. The Agent submits destination, date, budget, companion, and preference data to the attacker-controlled endpoint.
  5. The attacker returns forged prices, travel information, or jumpUrl values.
  6. The Agent incorporates the manipulated results and links into its trusted report.

Impact Assessment

An attacker with an appropriate network position may obtain confidentiality and in ...[truncated 459 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all use of NODE_TLS_REJECT_UNAUTHORIZED=0.
  2. Fail closed when certificate verification fails.
  3. Correct the server certificate chain, hostname, expiration, or local trust-store configuration.
  4. If a private certificate authority is required, configure only that trusted CA for the specific service.
  5. Do not disable verification globally for the entire Node.js process.
  6. Add strict endpoint and hostname validation.
  7. Validate returned URLs and treat all remote response fields as untrusted data.
  8. Produce a clear error and ask the user whether to retry after certificate configuration is repaired.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:82
Finding

Shell Command Injection Through Direct Interpolation of User Itinerary Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:82-93
Vulnerability Type: User-controlled data embedded in shell command examples
Risk Level: High

Code Snippet

bash
flyai search-flight --origin "[USER_ORIGIN]" --destination "[USER_DESTINATION]" --dep-date [DATE] --back-date [DATE] --sort-type 3

flyai search-hotel --dest-name "[USER_AREA]" --check-in-date [DATE] --check-out-date [DATE] --sort price_asc

flyai search-poi --city-name "[USER_CITY]" --poi-level 4

flyai ai-search --query "[USER_ITINERARY_DESCRIPTION]"

The bracketed values represent fields collected directly from the user. The source provides no safe argument-construction, validation, or escaping procedure.

Technical Analysis

The Skill presents commands as shell strings and directs the Agent to replace placeholders with user-supplied values. Quotation marks alone are not a sufficient defense if an attacker can supply quote characters, shell substitutions, command separators, redirections, or line breaks.

For example, a malicious itinerary description can terminate the quoted argument and append another shell command. If the Agent passes the resulting string to a shell, the shell interprets the injected syntax before or alongside the intended flyai invocation.

The issue is especially significant for the semantic-search command because it accepts a complete natural-language itinerary. The expected input is broad and may contain arbitrary punctuation, making restrictive validation less likely unless explicit safe process-spawning requirements are added.

Attack Path

  1. An attacker supplies a crafted origin, destination, city, area, or itinerary description containing shell metacharacters.
  2. The Agent substitutes that text into one of the documented command strings.
  3. The Agent executes the constructed command through a shell.
  4. The malicious input terminates or modifies the intended argument.
  5. The shell executes a ...[truncated 806 chars]
Remediation
View remediation

Remediation Suggestions

  1. Never construct a shell command by interpolating user input.
  2. Invoke the executable through a process API using a fixed argument array and with shell processing disabled.
  3. Pass each user value as exactly one argument.
  4. Validate structured fields:
    • Require supported date formats.
    • Normalize city and airport identifiers.
    • Reject control characters and unexpected line breaks.
    • Apply reasonable length limits.
  5. Treat natural-language itinerary text as opaque data rather than executable syntax.
  6. If only a shell interface is available, use a well-tested platform-specific escaping library; argument-array execution remains preferred.
  7. Run the CLI in a sandbox with minimal filesystem, credential, and network permissions.
  8. Add regression tests using quotes, semicolons, command substitution syntax, redirections, and multiline input.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
reference/user-profile-storage.md:7
Finding

Automatic Access to Persistent Travel and Family Profile Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:52-57, 135-169, 190-194; detailed workflow in reference/user-profile-storage.md:7-32, 36-58, 64-116, 155-165
Vulnerability Type: Privacy-sensitive persistent-state access beyond minimum task requirements
Risk Level: Medium

Code Snippet

python
search_memory(
    query="user travel profile",
    category="user_hobby",
    keywords="flyai",
    depth="shallow"
)
text
read_file(file_path="~/.flyai/user-profile.md")
bash
mkdir -p ~/.flyai
cat ~/.flyai/user-profile.md

The documented profile format can contain residence, preferred airport, budget, usual party size, child or family details, accommodation preferences, previously visited cities, pet requirements, and accessibility needs.

Technical Analysis

The Skill instructs the Agent to search persistent memory at startup and to fall back to reading a profile from the user's home directory. This read occurs automatically rather than after explicit per-session consent.

Some profile data is useful for travel planning, but the complete record can exceed what is necessary to inspect a particular itinerary. Family composition, child age, residence, past destinations, accessibility needs, and budget are privacy-sensitive when combined.

The write workflow is comparatively safer because it instructs the Agent to ask before saving a newly discovered preference. Nevertheless, the storage design does not define retention periods, deletion procedures, encryption, file permissions, tenant isolation, field-level minimization, or rules preventing unrelated profile details from entering later tool requests.

No evidence in the audited repository proves that profile data is intentionally exfiltrated. The confirmed problem is automatic broad access and insufficiently constrained persistence.

Attack Path

  1. A user activates the Skill to inspect an itinerary.
  2. Before determin ...[truncated 1032 chars]
Remediation
View remediation

Remediation Suggestions

  1. Obtain explicit, informed consent before reading persistent memory or local profile files.
  2. Ask only for fields necessary to evaluate the current itinerary.
  3. Load profile fields selectively rather than importing the entire record.
  4. Explain what will be read, why it is needed, where it is stored, and whether it may be sent to a third party.
  5. Keep write consent granular and allow users to review the exact value before storage.
  6. Define retention periods and provide view, edit, export, and deletion controls.
  7. Isolate records by user and Skill to prevent cross-user or cross-purpose access.
  8. Apply restrictive local file permissions and encryption where appropriate.
  9. Exclude child details, accessibility information, precise residence, and travel history unless specifically required and authorized.
  10. Prevent profile data from entering remote search queries unless the user separately consents to that disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (32)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The instruction to use NODE_TLS_REJECT_UNAUTHORIZED=0 disables TLS certificate validation, allowing man-in-the-middle interception or tampering of flight, hotel, and booking-link responses. In a travel-booking context this is especially dangerous because manipulated results could redirect users to fraudulent prices, malicious links, or altered itinerary data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires a global npm install/upgrade of a CLI before performing itinerary checks, even though that task does not inherently require modifying the host system. This expands the attack surface by executing package-manager operations, trusting the npm supply chain, and potentially changing the user's environment for a low-risk content-analysis task.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The rule explicitly recommends disabling TLS certificate validation via NODE_TLS_REJECT_UNAUTHORIZED=0 to work around SSL failures. This removes server identity verification and enables man-in-the-middle interception or tampering of flight, pricing, and itinerary-related network traffic, which is especially risky for a diagnostic skill that may influence user travel decisions based on fetched data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The markdown instructs bypassing SSL certificate verification with no warning or constraints, normalizing an unsafe practice as standard failure handling. That guidance can propagate directly into implementation and operational behavior, exposing all HTTPS requests in that process to spoofing and content tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to perform a global npm install/upgrade and even suggests using sudo, but gives no meaningful warning that this will modify the local system. This is unsafe operational guidance because it can lead users or agents to make privileged environment changes for a routine advisory skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill reads persistent user profile data and falls back to a local file containing travel preferences, which is beyond what is necessary for a one-off itinerary review. Accessing historical preference data without strong minimization and transparency increases privacy risk and can expose unrelated sensitive information about the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill reads persistent user profile data at startup without presenting a clear privacy notice in the skill description or workflow. That creates an unsafe default where personal travel preferences may be accessed automatically, contrary to user expectations for a simple itinerary check.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions direct the agent to retain and use user profile information from memory or local files beyond the immediate itinerary-checking task. Persistent storage and retrieval of behavioral preference data increases privacy exposure and creates a larger target if memory or files are later accessed improperly.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
100% confidence
Finding

NODE_TLS_REJECT_UNAUTHORIZED=0 is an unsafe default because it disables certificate verification for TLS connections. That permits interception and manipulation of supposedly secure network traffic, which is especially severe here because the skill uses the network to obtain prices and booking links that influence user purchases.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

步骤 4:调用 FlyAI 能力验证

SSL 证书问题处理: 命令前加 NODE_TLS_REJECT_UNAUTHORIZED=0

bash
# 验证机票价格

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The memory design explicitly stores travel style, budget level, interests, destination history, notes, pitfalls, and optimization feedback as an ongoing knowledge record. This goes beyond transient processing and creates a persistent profile of the user's habits and preferences, which raises privacy and misuse risks if not tightly governed.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Although the save flow mentions prompting for confirmation, it still instructs the agent to persist newly discovered preferences to memory or a local file. Persisting inferred preferences from conversation can create sensitive behavioral records, especially when stored locally outside a centrally governed permission model.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill proposes sending user itinerary details to external search services to validate flights, hotels, and POIs, but it does not disclose that trip data may be transmitted outside the system. Travel plans can contain sensitive personal information such as destinations, dates, and inferred absence-from-home windows, so undisclosed sharing creates privacy and trust risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is described as an itinerary checker, but the example output goes beyond analysis into steering the user toward specific booking actions via direct third-party links. That expands the skill's effective behavior from advisory to transactional influence, which can mislead users, create affiliate/steering concerns, and expose them to unvetted external sites without clear disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Direct booking links and acceptance actions can steer users into purchases, but the example lacks any warning that the skill may influence spending decisions or redirect to external booking sites. In a travel context, users may over-trust the AI's recommendations and click through without understanding that they are leaving the assistant's trust boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example includes direct links for flights, hotels, and tickets even though such booking flows are not necessary for itinerary validation. This creates unnecessary redirection to third-party commerce endpoints, increasing phishing, affiliate manipulation, and trust-boundary risks in a context where users may believe recommendations are purely diagnostic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire output template is written in Chinese and presents a fixed-language reporting format, with no indication that the user can choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template instructs the agent to append booking CTAs and Feizhu jump links as part of a 'trip health check' report, expanding a read-only evaluation skill into transactional steering. This creates scope creep and can bias the agent toward conversion behavior, potentially causing unauthorized commercial redirection or recommendations that are not strictly necessary for the requested diagnostic task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dedicated '快速预订入口' section is a conversion-oriented output block that is not required to assess itinerary quality. Embedding purchase links in the final response can manipulate user flow, blur the boundary between neutral analysis and affiliate/commercial action, and increase the risk of the skill performing actions outside its declared purpose.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

NODE_TLS_REJECT_UNAUTHORIZED=0 is an unsafe default because it disables certificate checks process-wide for Node.js HTTPS connections. In this skill's context, that is more dangerous because external travel search and validation data could be silently altered, causing inaccurate recommendations, manipulated prices, or exposure of sensitive itinerary details.

Content

Scanner excerpt · reference/scoring-rules.md (reported line 37)May include surrounding context.

md
| FlyAI 搜索无结果 | 尝试调整搜索条件,或说明数据限制 |
| 境外目的地数据不全 | 说明可能存在数据覆盖问题,基于已有信息分析 |
| 用户未提供价格 | 只做路线和时间分析,跳过价格体检 |
| SSL证书验证失败 | 使用 NODE_TLS_REJECT_UNAUTHORIZED=0 绕过验证 |

## 诊断状态判定

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document expands a trip-checking skill into persistent collection and storage of user travel profile data, including family and preference details, which is not necessary for a one-off itinerary health check. This creates privacy and data-minimization risks because the skill is instructed to retain personal information beyond the immediate task without clear necessity or safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document describes persistent storage of personal travel information but does not provide an explicit privacy warning, retention notice, or clear user-consent requirement. Users may unknowingly disclose sensitive profile details that are then retained across sessions, creating avoidable privacy and compliance risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance explicitly instructs the agent to write user profile data to Qoder Memory or local disk as a fallback behavior. For a trip-checking skill, this persistence capability is excessive and increases the chance of unauthorized retention, cross-session profiling, or unintended reuse of personal travel data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The local-file mode instructs creation and maintenance of a profile file under ~/.flyai/user-profile.md containing personal travel preferences and potentially sensitive household details. Writing such data to a predictable home-directory path creates persistent local exposure to other software, users, backups, or unintended disclosure, especially because no access controls or encryption are specified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented local path and file format encourage writing personal profile data to an unencrypted markdown file without warning the user that it will persist on disk. This is dangerous because travel preferences, household composition, and home-city information can be exposed through local compromise, shared machines, syncing services, or backups.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The instruction to create ~/.flyai establishes session persistence for personal profile data in the user's home directory. In the context of a trip-checking skill, this persistence is broader than necessary and increases the risk of silent accumulation of user data across sessions and tools.

Content

Scanner excerpt · reference/user-profile-storage.md (reported line 73)May include surrounding context.

如果 ~/.flyai/ 目录不存在,需要先创建:

bash
mkdir -p ~/.flyai

文件格式

Static analysis

No suspicious patterns detected.