多目的地航线组合比价助手
PassAudited by VirusTotal on Apr 1, 2026.
Findings (1)
The skill bundle is designed for multi-city flight optimization but contains a significant security risk by explicitly instructing the AI agent to execute shell commands with `NODE_TLS_REJECT_UNAUTHORIZED=0` (found in `SKILL.md`, `reference/flyai-commands.md`, and `reference/tools-guide.md`). This disables SSL/TLS certificate verification, exposing the agent to Man-in-the-Middle (MitM) attacks when interacting with flight search APIs. While this appears to be a functional workaround for environment-specific connectivity issues rather than intentional malice, it represents a high-risk security vulnerability.
