Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Plan Bali Travel — Flights, Hotels, Attractions, Temples, Beaches, Villas & Itineraries

v3.2.0

Plan your Bali dream trip — Ubud rice terraces, Seminyak beach clubs, Uluwatu temple sunsets, Nusa Penida cliffs, and spiritual yoga retreats. Also supports:...

0· 61·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for xiejinsong/bali-travel.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Plan Bali Travel — Flights, Hotels, Attractions, Temples, Beaches, Villas & Itineraries" (xiejinsong/bali-travel) from ClawHub.
Skill page: https://clawhub.ai/xiejinsong/bali-travel
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install bali-travel

ClawHub CLI

Package manager switcher

npx clawhub@latest install bali-travel
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's stated purpose (Bali travel planning) matches the CLI-driven workflow described (search-flight, search-hotel, search-poi). However the description claims 'Powered by Fliggy (Alibaba Group)' while the runtime tooling is a different package name ('flyai' / @fly-ai/flyai-cli), which is an unexplained mismatch and worth verifying. Requiring a third-party CLI is plausible for this purpose, but the provenance of that CLI is not declared in metadata.
!
Instruction Scope
SKILL.md mandates installing and running an external npm CLI at runtime, requires that every result come from that CLI (never use training data), and defines a persistent execution log format. The runbook explicitly suggests appending logs to .flyai-execution-log.json if filesystem writes are available — this writes persistent data to the host. The instructions also require strict output rules (every result must include a booking link) and a forced re-execute behavior if those rules aren't met, which could cause repeated network calls. These runtime actions extend beyond simple query-to-result behavior and have privacy/persistence implications.
!
Install Mechanism
There is no declared install spec in the skill metadata, yet SKILL.md instructs the agent/user to run 'npm i -g @fly-ai/flyai-cli' if flyai is not installed. Installing a global npm package at runtime is a moderate-to-high risk action because it fetches and executes third-party code from the npm registry; the package's origin, publisher, and trustworthiness are not provided. The install instruction being embedded in runtime instructions (not in a vetted install spec) reduces transparency and control.
Credentials
The skill declares no required environment variables or credentials, which is consistent with the metadata. However booking and booking-link creation typically require service credentials or redirects to vendor pages. The skill does not describe how authentication for bookings is handled, whether the flyai CLI will prompt for credentials, or whether any tokens might be stored in the environment or config files. The absence of declared credential requirements is plausible but leaves open questions that should be answered before use.
!
Persistence & Privilege
The runbook includes a schema for an execution log and explicitly suggests appending such logs to a host file (.flyai-execution-log.json) if filesystem writes are available. This grants the skill the ability to persist user queries, parameters, and command outputs locally. While not 'always:true', the skill does request persistent local writes when possible, which is a meaningful privilege and could contain personal travel data.
What to consider before installing
This skill is plausibly a travel helper but has a few red flags you should consider before installing or running it: - The skill requires installing a third-party npm package at runtime (npm i -g @fly-ai/flyai-cli). Verify the package owner, read its npm page and source repository, and confirm it's published by the expected vendor (the description references Fliggy/Alibaba but the package name differs). - The runbook may write persistent logs to your filesystem (.flyai-execution-log.json). If you care about privacy, run the skill in a sandbox/container or ensure the agent cannot write to your home directory. - The skill does not declare how bookings/authentication are handled. Expect the CLI to possibly prompt for credentials or to store tokens locally — ask the skill author whether credentials are needed and where they are stored. - Because the skill forces re-execution until a specific link format appears, it could generate repeated network calls; monitor network activity when first running it. Recommended actions before proceeding: - Inspect the @fly-ai/flyai-cli package on npm/GitHub to confirm publisher and code quality. - Run the CLI installation and initial tests in an isolated environment (container or VM) first. - Ask the skill author to clarify the Fliggy vs flyai provenance, booking authentication flow, and log retention policy. - If you cannot verify the CLI origin, do not install the package globally on a production machine.

Like a lobster shell, security has layers — review code before you run it.

latestvk977sfee35g9z6mc25j4834jkn84sfe6
61downloads
0stars
1versions
Updated 2w ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI command output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: bali-travel

Overview

Plan your Bali dream trip — Ubud rice terraces, Seminyak beach clubs, Uluwatu temple sunsets, Nusa Penida cliffs, and spiritual yoga retreats.

When to Activate

User query contains:

  • English: "Bali", "Ubud", "Seminyak", "Kuta"
  • Chinese: "巴厘岛", "乌布", "库塔"

Do NOT activate for: general SE Asia → explore-southeast-asia

Prerequisites

npm i -g @fly-ai/flyai-cli

Parameters

This skill orchestrates multiple CLI commands. See each command's parameters below:

search-flight

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--dep-date-startNoStart of flexible date range
--dep-date-endNoEnd of flexible date range
--back-dateNoReturn date for round-trip
--sort-typeNo3 (price ascending)
--max-priceNoPrice ceiling in CNY
--journey-typeNoDefault: show both
--seat-class-nameNoCabin class (economy/business/first)
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)

Sort Options

ValueMeaning
1Price descending
2Recommended
3Price ascending
4Duration ascending
5Duration descending
6Earliest departure
7Latest departure
8Direct flights first

search-hotel

Parameters

ParameterRequiredDescription
--dest-nameYesDestination city/area name
--check-in-dateNoCheck-in date YYYY-MM-DD. Default: today
--check-out-dateNoCheck-out date. Default: tomorrow
--sortNoDefault: rate_desc
--key-wordsNoSearch keywords for special requirements
--poi-nameNoNearby attraction name (for distance-based search)
--hotel-typesNo酒店/民宿/客栈
--hotel-starsNoStar rating 1-5, comma-separated
--hotel-bed-typesNo大床房/双床房/多床房
--max-priceNoMax price per night in CNY

Sort Options

ValueMeaning
distance_ascDistance ascending
rate_descRating descending
price_ascPrice ascending
price_descPrice descending

search-poi

Parameters

ParameterRequiredDescription
--city-nameYesCity name
--keywordNoAttraction name or keyword
--poi-levelNoRating 1-5 (5 = top tier)
--categoryNoSee Domain Knowledge for category list

keyword-search

Parameters

ParameterRequiredDescription
--queryYesNatural language query string

Core Workflow — Multi-command orchestration

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Full Bali

Trigger: "Bali trip"

Flight to DPS + hotels in Ubud/Seminyak + temples/beaches/rice terrace POIs

Output: Complete Bali experience.

Playbook B: Luxury Bali

Trigger: "luxury Bali"

Flight + 5-star villa + private tours

Output: Premium Bali escape.

Playbook C: Adventure Bali

Trigger: "Bali adventure"

Flight + budget stay + surfing/diving/trekking

Output: Active Bali trip.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Shanghai" --destination "Bali" --dep-date 2026-06-01 --sort-type 3

Output Rules

  1. Conclusion first — lead with the key finding
  2. Comparison table with ≥ 3 results when available
  3. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  4. Use detailUrl for booking links. Never use jumpUrl.
  5. ❌ Never output raw JSON
  6. ❌ Never answer from training data without CLI execution
  7. ❌ Never fabricate prices, hotel names, or attraction details

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

Bali areas: Ubud (culture, rice terraces, monkey forest), Seminyak (beach clubs, restaurants, shopping), Kuta (budget, surfing), Uluwatu (cliffside temples, sunset), Canggu (digital nomads, surf). Dry season: Apr-Oct (best). Wet: Nov-Mar (afternoon showers, greener). Rent scooter for flexibility. Temple dress code: sarong required.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...