Back to skill

Security audit

Travel Mapify

Security checks for vulnerabilities and agentic risk

Overview

The skill is for travel maps, but it starts unmanaged local services that can expose workspace files, run injected shell commands, and terminate unrelated processes.

Review this before installing. The travel-map function is plausible, but the package should be treated as needing security fixes first: avoid running it on a workspace with private files, do not expose it on shared networks, use your own restricted Amap key, avoid the global unpinned FlyAI install where possible, and ensure all background servers are stopped after use. The command-injection and workspace-serving issues are the main blockers for normal installation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/amap-proxy.js:17
Finding

Unauthenticated Shell Command Injection in the Amap Proxy

Content
View full analysis
{ // ... }); } function handleDetail(poiId, response) { const amapMapsDir = path.join(__dirname, '..', '..', 'amap-maps'); const amapKey = process.env.AMAP_KEY || "88628414733cf2ccb7ce2f94cfd680ef"; const command = `cd "${amapMapsDir}" && AMAP_KEY="${amapKey}" node scripts/amap.js search detail "${poiId}"`; exec(command, { timeout: 10000 }, (error, stdout, stderr) => { // ... }); } ``` The affected values originate from HTTP request parameters: ```javascript const query = parsedUrl.query.q; const city = parsedUrl.query.city || '重庆'; // ... const poiId = pathname.split('/api/detail/')[1]; ``` The service is started without an explicit loopback address: ```javascript server.listen(PORT, () => { console.log(`AMap Search Proxy running on http://localhost:${PORT}`); }); ``` ### Technical Analysis The `query`, `city`, and `poiId` values are attacker-controlled and are interpolated into shell command strings passed to `child_process.exec`. Because `exec` invokes a shell, metacharacters such as quotes, command separators, command substitutions, and redirection operators are interpreted by the operating system. Placing `query` inside double quotes does not make it safe. An attacker can inject a closing quote or use shell substitut ...[truncated 1219 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/main_travel_mapify_enhanced.py:85
Finding

OpenClaw Workspace Exposed Through an Automatically Started HTTP Server

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ensure_servers_running.py:24
Finding

Automatic Termination of Unrelated Processes Occupying Fixed Ports

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
scripts/ensure_servers_running.py:55
Finding

Detached Servers Persist After the Skill Operation Completes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_from_optimized_template.py:38
Finding

Script Injection and DOM XSS in Generated Travel Maps

Content
View full analysis
${index + 1}
${poi.name}
`; poiListDiv.innerHTML = html; ``` Amap search results are handled similarly: ```javascript html += `

${name}

${address} ${rating ? '⭐' + rating : ''}

`; resultsDiv.innerHTML = html; ``` Hotel API data is also inserted into HTML and URL attributes: ```javascript hotelItem.innerHTML = `
🏨
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hotel-search-server.py:22
Finding

Any Website Can Trigger FlyAI CLI Operations Through the Local Hotel Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/amap-proxy.js:22
Finding

Hard-Coded Amap API Key Exposed in Server and Browser Code

Content
View full analysis
``` ### Technical Analysis The API key is committed to project source and embedded in generated browser content. Anyone with access to the project or a generated map can extract and reuse it. Although some map providers use client-visible keys, such keys must be specifically configured as restricted browser keys. Reusing the same value in server-side requests and public client code removes meaningful confidentiality and broadens abuse opportunities. ### Attack Path 1. An attacker downloads the project or receives a generated HTML map. 2. The attacker reads the API key from the JavaScript or script URL. 3. The attacker submits unrelated Amap requests using that key. 4. Requests consume the owner's quota or trigger provider-side abuse controls. ### Impact Assessment The key may be abused for unauthorized API consumption, quota exhaustion, service disruption, and possible billing or account-reputation impact. The practical scope depends on restrictions configured at the Amap provider. ]]>
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:187
Finding

Unpinned Global Installation of a Third-Party CLI

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A skill that mainly packages CLI arguments or returns placeholders while claiming advanced travel-map, hotel-search, and AI-Vision functionality is misleading to both users and automated execution systems. This can result in over-trust, improper deployment decisions, and accidental exposure of user inputs to unreviewed external/manual processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file describes automatic city recognition using Chinese place names and states that fallback behavior uses Shanghai as the default city, indicating a locale-specific behavior. There is no natural-language disclosure that the skill is intended specifically for Chinese locations or that users may choose another locale, which can violate language/locale policy when the constraint is not explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The installation guide states that a built-in default Amap API key is included and that no user key is required, but it does not warn users that travel queries and place lookups may be sent to an external mapping service under someone else's credentials. This creates privacy, accountability, and abuse-risk concerns because users may unknowingly transmit sensitive location data and rely on a shared secret they do not control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documentation describes use of a local Amap proxy and Python HTTP server but gives no warning about possible network exposure, access scope, or transmission of user-provided travel/location data. In a travel-mapping skill, queried destinations and itineraries can be sensitive, so failing to disclose service binding behavior and data flow can lead to unintended exposure on shared or misconfigured systems.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises behaviors that imply file, network, environment, and shell access, yet it declares no explicit tool scope or permissions. This weakens least-privilege guarantees and makes it easier for a host agent or reviewer to underestimate the operational power of the skill, especially since it also mentions server management and external API access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The skill explicitly describes persistent per-map state and localStorage isolation by unique map ID, which means user itinerary data, hotel searches, and related selections are retained across sessions. Even though scoped storage is better than global storage, session persistence of travel data is still privacy-relevant because it can expose sensitive locations and plans to other local users or scripts on the same browser profile.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: flyai-travelmapify
version: 2.2.2
description: Create interactive travel route maps from location names with real FlyAI hotel search. Supports AI Vision analysis of travel planning images.
author: rudy2steiner
license: MIT
tags: [travel, maps, routing, geocoding, flyai, hotels, unique-id, server-management, interactive, ai-vision]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages image-based workflows without clearly warning users that uploaded travel images may be analyzed by an AI Vision system. Travel screenshots and itinerary photos can contain sensitive personal data, locations, names, booking details, or other metadata that users may not expect to be sent for AI analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation does not clearly warn that real itinerary/location data will be transmitted to external mapping and hotel services. Because travel plans reveal highly sensitive behavioral information, undisclosed network transmission increases privacy risk and may violate user expectations or policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation inconsistently states that the skill itself analyzes images while also saying image processing is handled externally by the agent's AI Vision capability. This ambiguity hides who processes uploaded travel images and where sensitive image data goes, which is a real privacy and trust-boundary issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The UI text is presented entirely in Chinese and the map is explicitly configured with lang: 'zh_cn', with no option for users to choose another language. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless it is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The page sends user-entered search queries to a local HTTP service on localhost:8769 and later sends destination and travel dates to another local HTTP service on localhost:8780, but the UI does not clearly disclose that these inputs are being transmitted to backend services. Even though the targets are local, this is still a privacy-relevant data flow because itinerary and date information may be sensitive and users are not given meaningful notice or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code stores POIs and travel dates in localStorage under a derived map identifier without notifying the user or offering a retention/control mechanism. localStorage is persistent and readable by any script running in the same origin, so travel plans and dates can remain exposed longer than users expect, especially if other content on the origin is compromised.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · flyai-travelmapify.py (reported line 44)May include surrounding context.

python
try:
        # Execute the main script
        result = subprocess.run(cmd)
        sys.exit(result.returncode)
    except KeyboardInterrupt:
        print("\nOperation cancelled by user", file=sys.stderr)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L062 sets lang: 'zh_cn', which forces a specific locale in the JavaScript API example. Under the policy, locale constraints should be optional, user-selectable, or clearly justified as region-specific; this document does not provide that justification or opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide recommends disabling browser security protections (--allow-file-access-from-files and relaxing Firefox origin policy), which weakens same-origin and local file safeguards beyond this specific skill. Although it notes this is 'not recommended for production' and calls it a 'security risk,' it still provides actionable bypass steps that users may apply broadly, increasing exposure to malicious local or web content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest claims the skill creates interactive travel route maps with real FlyAI hotel search and AI Vision analysis, but this file only exposes search/detail endpoints for an external AMap helper script. That is a materially narrower and different behavior than the user-facing capability promised in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/amap-proxy.js:25