Back to skill

Security audit

本月轻松旅行盲盒

Security checks for vulnerabilities and agentic risk

Overview

This travel skill is mostly coherent, but it asks users or agents to install an unpinned global CLI and even suggests sudo, which is too much authority for a weekend trip recommender.

Review before installing. The travel features are understandable, but do not run the suggested sudo/global npm install path unless you fully trust the FlyAI CLI and its current npm release. Safer packaging would pin the CLI version, avoid sudo, avoid global installation, and fail gracefully when the dependency is unavailable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:179
Finding

Mandatory Third-Party Branding Injected into Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:179-182
Vulnerability Type: Mandatory output manipulation
Risk Level: Medium

Vulnerable Code

markdown
---
*Data source: based on fly.ai real-time search results; weather information is for reference only. Check the latest forecast before departure.*
✈️ Powered by FlyAI

Technical Analysis

The skill defines a fixed response template that requires FlyAI attribution and promotional branding in the agent's final answer. This instruction is unrelated to the essential function of calculating weekends and recommending destinations, and it applies regardless of whether the user requested promotional content.

Because the content is part of the agent prompt, loading the skill changes the output behavior of the current session. The agent is instructed to reproduce third-party branding rather than independently deciding whether attribution is relevant. This is classified as instruction hijacking because skill text imposes an external output objective on the host agent.

Attack Path

  1. A user request activates the travel skill.
  2. The host agent loads the skill prompt and mandatory output template.
  3. The agent performs the travel recommendation workflow.
  4. The fixed template causes the final response to include FlyAI attribution and branding.
  5. The user receives promotional content that was not explicitly requested.

Impact Assessment

The issue does not grant operating-system privileges or access to confidential data. Its scope is limited to the current agent session and generated responses. However, it compromises response integrity by allowing the skill author to mandate third-party promotional content and override the host agent's normal discretion over final-answer composition.

Remediation
View remediation

Remediation Suggestions

  • Remove mandatory promotional branding from the output template.
  • Include source attribution only when FlyAI data was actually used.
  • Clearly distinguish factual source attribution from promotional language.
  • Allow the host agent to select an appropriate attribution format.
  • Do not require fixed third-party text in every user-facing response.

T08 · Insecure Dependencies

Error
Location
package.json:15
Finding

Mutable Unpinned Dependency Installed Globally

Content
View full analysis

Vulnerability Details

File Location: package.json:15-17; supporting installation instruction at SKILL.md:256-263
Vulnerability Type: Unpinned third-party dependency and unsafe global installation
Risk Level: High

Vulnerable Code

package.json:

json
"dependencies": {
  "@fly-ai/flyai-cli": "latest"
}

SKILL.md:

markdown
#### 2. Install FlyAI CLI
**Installation command**:

npm install -g @fly-ai/flyai-cli

text

**Post-installation verification**:

flyai --help

text

Technical Analysis

The dependency uses the mutable latest version selector rather than an audited exact version. Each installation can therefore resolve to different package contents without any project change or renewed review.

The documented workflow installs the package globally. npm installation may execute package lifecycle scripts, meaning a compromised or unexpectedly modified release could execute code with the installing user's privileges. Global installation also changes shared user-level tooling outside the project and bypasses the isolation normally provided by a project-local dependency and lockfile.

No lockfile or integrity-pinned artifact is present in the audited project. Consequently, the reviewed source does not uniquely determine the code that will be downloaded and executed during installation.

Attack Path

  1. The skill checks whether the flyai executable is available.
  2. If it is absent, the workflow directs installation with npm install -g @fly-ai/flyai-cli.
  3. npm resolves the mutable latest tag at installation time.
  4. An attacker compromises the package, a maintainer account, or a newly published release associated with that tag.
  5. npm downloads the altered package and executes any applicable lifecycle scripts.
  6. Malicious code runs with the privileges of the user performing the installation and can modify globally installed user tooling.

...[truncated 365 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace latest with an audited exact version.
  • Commit a package lockfile containing resolved versions and integrity hashes.
  • Install the dependency locally rather than globally.
  • Require explicit user approval before downloading or installing external software.
  • Disable npm lifecycle scripts where they are unnecessary, such as with --ignore-scripts.
  • Execute the CLI in a restricted sandbox with minimal filesystem, network, and credential access.
  • Establish a controlled update process that reviews and tests each dependency version before adoption.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:268
Finding

Recommendation to Install a Mutable npm Package with Root Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:268-273
Vulnerability Type: Privileged third-party package installation
Risk Level: Critical

Vulnerable Code

markdown
| Situation | Handling method |
|-----|---------|
| **npm is unavailable** | Ask the user to install Node.js (https://nodejs.org/) |
| **Insufficient permissions** | Recommend `sudo npm install -g @fly-ai/flyai-cli` or use nvm to manage Node |
| **Network problem** | Recommend checking the network or using the regional mirror `npm config set registry https://registry.npmmirror.com` |

Technical Analysis

The permission-error fallback recommends running a global npm installation through sudo. This causes npm and any package lifecycle scripts to execute with root privileges.

Root access is not necessary for the skill's legitimate travel-search function. The recommendation therefore violates least privilege and combines elevated execution with the mutable dependency identified in package.json. If the package or one of its transitive dependencies is compromised, installation scripts may obtain unrestricted control over the host.

Merely offering nvm as an alternative does not mitigate the unsafe recommendation because the privileged command remains explicitly presented as an accepted recovery path.

Attack Path

  1. The flyai executable is unavailable.
  2. The user attempts the documented global installation.
  3. The installation fails because the account cannot modify the global npm directory.
  4. The skill recommends retrying with sudo.
  5. The user executes sudo npm install -g @fly-ai/flyai-cli and authorizes elevation.
  6. npm downloads the package and its transitive dependencies.
  7. Any malicious lifecycle script executes as root.
  8. The malicious code can modify system files, install persistent components, access protected data, or replace trusted executables.

Impact Assessment

Successful exploitatio ...[truncated 370 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the sudo npm install -g recommendation entirely.
  • Use a project-local, exact-version dependency installed under an unprivileged account.
  • Prefer an unprivileged Node.js version manager when user-scoped installation is required.
  • Require explicit informed consent before any dependency installation.
  • Run external tooling in a sandbox or container without root access.
  • Restrict filesystem, credential, and network access to the minimum required for travel searches.
  • Document a safe failure mode that stops execution instead of requesting privilege elevation.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow expands from generating travel suggestions into checking the host environment (which flyai) and installing missing software, which is a capability escalation unrelated to the user task. In skill context this is more dangerous because ordinary travel prompts could now cause execution paths that inspect and alter the runtime host, increasing attack surface and persistence risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs the agent to modify the host by globally installing an npm package (npm install -g @fly-ai/flyai-cli) even though the skill’s business purpose is only travel recommendation. This creates a software supply-chain and environment-integrity risk: a content-triggered skill should not introduce persistent system changes or fetch executable code from the network at runtime, especially with no pinning, checksum verification, or sandboxing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The agent prompt and the surrounding skill instructions are written to operate in Chinese, and the examples, output structure, and user interaction patterns assume Chinese-language use. There is no indication that users may choose another language, nor is there a documented reason that the skill must be Chinese-only.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest regex patterns include generic phrases such as '推荐', '去哪', '旅行', '周边', and English equivalents like 'recommend' and 'travel', combined in broad ways that can match many ordinary planning requests. The file does not provide exclusion conditions or negative examples to clarify when the skill should not activate, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
99% confidence
Finding

The skill explicitly recommends sudo npm install -g @fly-ai/flyai-cli, encouraging privileged execution of network-fetched code. In this context, a travel recommendation skill has no legitimate reason to request root-level package installation; if followed, this could compromise the host, alter global binaries, or enable persistent malicious code through dependency-chain abuse.

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
| 情况 | 处理方式 |
|-----|---------|
| **npm 未安装** | 提示用户先安装 Node.js (https://nodejs.org/) |
| **权限不足** | 建议使用 `sudo npm install -g @fly-ai/flyai-cli` 或使用 nvm 管理 Node |
| **网络问题** | 建议用户检查网络或使用国内镜像 `npm config set registry https://registry.npmmirror.com` |

**注意**:此步骤只在首次使用时执行,后续调用会直接跳过。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description is entirely in Chinese and presents the skill as operating in that language, but there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This creates a natural-language policy concern because it may impose a language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Using the dependency version specifier "latest" makes builds non-deterministic and can silently pull in newly published versions, including malicious or compromised releases. In an agent skill context, this increases supply-chain risk because future installs may execute different CLI code than was originally reviewed.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"author": "wuyun",
  "license": "MIT",
  "dependencies": {
    "@fly-ai/flyai-cli": "latest"
  }
}

Static analysis

No suspicious patterns detected.