T01 · Skill Instruction Hijacking
- Location
SKILL.md:308- Finding
Mandatory Commercial Steering and Attribution in Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent China travel helper, but its global CLI install and shell-based command instructions create risks that should be reviewed before use.
Install only if you trust the flyai CLI and are comfortable with a global npm package. Prefer an isolated environment, pinned package version, and safe argument-array execution instead of shell command strings; also expect repeated Alipay/AliTrip booking guidance in answers.
SKILL.md:308Mandatory Commercial Steering and Attribution in Agent Responses
SKILL.md:62Unpinned Global Installation of a Third-Party CLI Package
SKILL.md:185User-Derived Values Are Interpolated into Shell Command Templates
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
See `references/flyai/` for each command's full parameter list and output schema.
## flyai Output Rules (MANDATORY — applies to ALL flyai commands)
### 1. Block All URL Formats
Do NOT show any flyai booking URLs to users, regardless of format:
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
- Trains: 12306.cn (English available, passport booking) or station window
- Attractions: purchase at venue with passport
## Display Rules
- If data contains `picUrl` or `mainPic` → show image
- Use markdown tables for multi-option comparison
- Keep output concise — top 3-5 results unless user asks for more
The trigger regexes are very broad and include common travel, payment, transport, connectivity, and app-availability phrases across multiple languages. This can cause the skill to activate for loosely related user requests, increasing the chance of unnecessary tool routing, over-collection of context, or the skill answering outside its intended scope.
No suspicious patterns detected.