Back to skill

Security audit

Tongtu China Travel

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent China travel helper, but its global CLI install and shell-based command instructions create risks that should be reviewed before use.

Install only if you trust the flyai CLI and are comfortable with a global npm package. Prefer an isolated environment, pinned package version, and safe argument-array execution instead of shell command strings; also expect repeated Alipay/AliTrip booking guidance in answers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:308
Finding

Mandatory Commercial Steering and Attribution in Agent Responses

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:62
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:185
Finding

User-Derived Values Are Interpolated into Shell Command Templates

Content
View full analysis
/dev/null`). All commands output single-line JSON to stdout. See `references/flyai/` for each command's full parameter list and output schema. ``` ### Technical Analysis The skill directs the agent to execute commands through a shell while inserting values derived from user requests into textual command templates. Translation of locations or attraction names into another language is not equivalent to syntactic validation or shell escaping. The document does not require argument-array execution, strict allowlists, quote-safe encoding, or rejection of shell control characters. If an implementation follows these instructions using a shell command string, a crafted city, attraction, category, date, or other search value could terminate the intended argument and introduce shell syntax. Suppressing stderr with `2>/dev/null` may further reduce visibility into malformed commands or exploitation attempts. The weakness depends on the host implementation passing generated strings to a shell; execution through a direct process API with separate arguments would substantially mitigate it. ### Attack Path 1. An attacker submits a travel request containing a cra ...[truncated 1263 chars]
Remediation
View remediation
/dev/null` through shell syntax; configure process streams through the execution API instead. 6. Record execution failures and rejected inputs in security logs without storing unnecessary personal data. 7. Run the CLI with least privilege, restricted filesystem access, and only the network destinations required for travel searches. 8. Add automated tests containing quotes, separators, substitutions, newlines, and other shell metacharacters to verify that every value remains a single inert argument. ]]>
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
See `references/flyai/` for each command's full parameter list and output schema.

## flyai Output Rules (MANDATORY — applies to ALL flyai commands)

### 1. Block All URL Formats
Do NOT show any flyai booking URLs to users, regardless of format:

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
- Trains: 12306.cn (English available, passport booking) or station window
- Attractions: purchase at venue with passport

## Display Rules
- If data contains `picUrl` or `mainPic` → show image
- Use markdown tables for multi-option comparison
- Keep output concise — top 3-5 results unless user asks for more

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger regexes are very broad and include common travel, payment, transport, connectivity, and app-availability phrases across multiple languages. This can cause the skill to activate for loosely related user requests, increasing the chance of unnecessary tool routing, over-collection of context, or the skill answering outside its intended scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.