Back to skill

Security audit

Fliggy Search

Security checks for vulnerabilities and agentic risk

Overview

This travel-search skill is coherent, but it asks an agent to install an unpinned global CLI and automatically create or reuse a Fliggy login session without enough user consent or session-safety guidance.

Review before installing. Use this only if you are comfortable installing an unpinned global npm package and letting it create or reuse a Fliggy login session. Treat ~/.fliggy-session.json like sensitive account state, protect it from sharing/logging/backups, and clear it with fliggy login --clear when no longer needed. Confirm any login, booking, or account-linked action explicitly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–18 and line 24
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Complete Code Snippet

yaml
"install":
  [
    {
      "id": "node",
      "kind": "node",
      "package": "fliggy-cli",
      "bins": ["fliggy"],
      "label": "Install Fliggy CLI (npm)",
    },
  ],
bash
npm install -g fliggy-cli

Technical Analysis

The skill instructs the framework or user to install fliggy-cli from npm without specifying an exact version or package integrity hash. Consequently, installation resolves whatever release is associated with the package’s current distribution tag rather than a release that was reviewed with this skill.

npm packages can execute lifecycle scripts during installation. The use of a global installation also makes the package binary available outside the project and increases its potential effect on the user environment. The package implementation is not present in the audited project, so its installation scripts, browser automation, network destinations, and handling of the reusable ~/.fliggy-session.json authentication state cannot be verified.

This is a supply-chain weakness rather than evidence that the current package is malicious. Exploitation depends on compromise, replacement, or malicious publication of the external dependency.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, or the package publication process and releases a malicious version under the version range implicitly selected by the unpinned install.
  2. The skill framework or user follows the documented instruction:
    bash
    npm install -g fliggy-cli
    
  3. npm downloads the attacker-controlled release and may execute its lifecycle scripts with the installing user’s privileges.
  4. The installed global fliggy executable subsequently runs attacker-controlled code when the skill invokes login or search ...[truncated 977 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin fliggy-cli to an exact, reviewed version in both skill metadata and installation documentation, for example:
    yaml
    "package": "fliggy-cli@1.0.1"
    
    bash
    npm install --global fliggy-cli@1.0.1
    
  2. Verify the selected package artifact using npm registry integrity metadata or a separately maintained cryptographic checksum.
  3. Use a lockfile where the deployment model supports it and retain reviewed dependency metadata with the skill release.
  4. Prefer a project-local, sandboxed installation over a global installation to limit environmental impact.
  5. Disable npm lifecycle scripts during installation where compatible:
    bash
    npm install --ignore-scripts fliggy-cli@1.0.1
    
    If lifecycle scripts are required, audit them before permitting execution.
  6. Include or link to auditable source corresponding exactly to the pinned package artifact.
  7. Document the CLI’s expected network destinations, browser behavior, and session-file usage.
  8. Ensure ~/.fliggy-session.json is created with restrictive user-only permissions and is never logged or exposed to unrelated processes.
  9. Reconcile the skill version mismatch between SKILL.md (1.0.1) and _meta.json (1.0.0) to improve artifact provenance and release traceability.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs users to authenticate to a third-party service and persist an authenticated session in ~/.fliggy-session.json, but it provides no warning that this file contains reusable account state and may expose travel account access if read by other local users, backups, or tools. Because the skill is designed to automate logged-in searches and potentially booking-related actions, omission of session-storage and privacy guidance creates a real security and privacy risk rather than a purely informational issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes automatic browser login behavior and headless background operation against Fliggy without clearly warning that commands will initiate network requests, interact with a third-party website, and may use a stored authenticated session. In an agent setting, that omission is risky because users may not realize the tool is performing account-linked actions in the background, reducing informed consent and increasing the chance of unintended data disclosure or account activity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.