Security checks for vulnerabilities and agentic risk
Overview
This travel-search skill is coherent, but it asks an agent to install an unpinned global CLI and automatically create or reuse a Fliggy login session without enough user consent or session-safety guidance.
Review before installing. Use this only if you are comfortable installing an unpinned global npm package and letting it create or reuse a Fliggy login session. Treat ~/.fliggy-session.json like sensitive account state, protect it from sharing/logging/backups, and clear it with fliggy login --clear when no longer needed. Confirm any login, booking, or account-linked action explicitly.
The skill instructs the framework or user to install fliggy-cli from npm without specifying an exact version or package integrity hash. Consequently, installation resolves whatever release is associated with the package’s current distribution tag rather than a release that was reviewed with this skill.
npm packages can execute lifecycle scripts during installation. The use of a global installation also makes the package binary available outside the project and increases its potential effect on the user environment. The package implementation is not present in the audited project, so its installation scripts, browser automation, network destinations, and handling of the reusable ~/.fliggy-session.json authentication state cannot be verified.
This is a supply-chain weakness rather than evidence that the current package is malicious. Exploitation depends on compromise, replacement, or malicious publication of the external dependency.
Attack Path
An attacker compromises the npm package, a maintainer account, or the package publication process and releases a malicious version under the version range implicitly selected by the unpinned install.
The skill framework or user follows the documented instruction:
bash
npm install -g fliggy-cli
npm downloads the attacker-controlled release and may execute its lifecycle scripts with the installing user’s privileges.
The installed global fliggy executable subsequently runs attacker-controlled code when the skill invokes login or search
...[truncated 977 chars]
Remediation
View remediation
Remediation Suggestions
Pin fliggy-cli to an exact, reviewed version in both skill metadata and installation documentation, for example:
yaml
"package": "fliggy-cli@1.0.1"
bash
npm install --global fliggy-cli@1.0.1
Verify the selected package artifact using npm registry integrity metadata or a separately maintained cryptographic checksum.
Use a lockfile where the deployment model supports it and retain reviewed dependency metadata with the skill release.
Prefer a project-local, sandboxed installation over a global installation to limit environmental impact.
Disable npm lifecycle scripts during installation where compatible:
bash
npm install --ignore-scripts fliggy-cli@1.0.1
If lifecycle scripts are required, audit them before permitting execution.
Include or link to auditable source corresponding exactly to the pinned package artifact.
Document the CLI’s expected network destinations, browser behavior, and session-file usage.
Ensure ~/.fliggy-session.json is created with restrictive user-only permissions and is never logged or exposed to unrelated processes.
Reconcile the skill version mismatch between SKILL.md (1.0.1) and _meta.json (1.0.0) to improve artifact provenance and release traceability.
The skill explicitly instructs users to authenticate to a third-party service and persist an authenticated session in ~/.fliggy-session.json, but it provides no warning that this file contains reusable account state and may expose travel account access if read by other local users, backups, or tools. Because the skill is designed to automate logged-in searches and potentially booking-related actions, omission of session-storage and privacy guidance creates a real security and privacy risk rather than a purely informational issue.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The skill describes automatic browser login behavior and headless background operation against Fliggy without clearly warning that commands will initiate network requests, interact with a third-party website, and may use a stored authenticated session. In an agent setting, that omission is risky because users may not realize the tool is performing account-linked actions in the background, reducing informed consent and increasing the chance of unintended data disclosure or account activity.