Back to skill

Security audit

flyai-travelmapify

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to implement the stated travel-map and hotel-search functionality, but there are multiple inconsistencies and surprising behaviors (embedded Amap API key, implicit environment usage, and subprocess execution of other skill code) that merit caution before installing or running.

Key points to consider before installing/running: - Embedded API key: The package includes a default Amap API key hardcoded in docs and used as fallback in scripts. This is a red flag — the key may belong to someone else, may be rate-limited, or revoked. Prefer to remove the embedded key and supply your own Amap key via AMAP_KEY env var. - Undeclared environment use: The registry lists no required env vars, yet the code uses AMAP_KEY and respects OPENCLAW_WORKSPACE and other environment/path probing. Treat the skill as one that reads workspace files and system paths. - Subprocess execution of other skill code: scripts/amap-proxy.js runs node scripts in a relative 'amap-maps' directory using child process exec. That means this skill will execute code stored outside itself (the amap-maps skill). Audit the amap-maps scripts before running; they can run arbitrary Node.js code on your machine. - Local servers & exposed ports: The skill auto-starts local HTTP and hotel-search servers. Running it will open HTTP endpoints on your machine; run in an isolated environment (container or VM) if you have security concerns. - FlyAI CLI and system probing: The skill searches PATH and common Node.js/NVM/Homebrew locations to find FlyAI and may call it. If you do not trust FlyAI or want to avoid system-wide probing, run the skill in a controlled environment and inspect/limit network access. Recommended actions: 1. Review scripts that call exec/subprocess (amap-proxy.js, any hotel-search-server or scripts invoking FlyAI) to confirm they do not perform unexpected network I/O or exfiltration. 2. Replace/remove the built-in Amap API key; require the user to set AMAP_KEY explicitly. 3. Run the skill in an isolated container or VM for initial testing so it cannot access sensitive host files or services. 4. Ensure the dependent 'amap-maps' skill is present and audited; do not run if that directory is untrusted or contains unknown code. 5. If you need least privilege, avoid running the automatic server-start behavior and instead use the code selectively (e.g., run geocoding only) after inspection. Given the mix of reasonable functionality and several surprising/undeclared behaviors, proceed cautiously and audit the code and dependencies before use.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/amap-proxy.js:25

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/amap-proxy.js:22