Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

birthday-trip

v3.2.0

Book birthday trip flights, surprise travel and celebration flight deals with birthday getaway booking. Also supports: flight booking, hotel reservation, tra...

0· 60·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dingtom336-gif/birthday-trip.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "birthday-trip" (dingtom336-gif/birthday-trip) from ClawHub.
Skill page: https://clawhub.ai/dingtom336-gif/birthday-trip
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install birthday-trip

ClawHub CLI

Package manager switcher

npx clawhub@latest install birthday-trip
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to provide birthday-trip booking and explicitly requires use of a CLI ('flyai'). That matches the stated purpose. However the SKILL.md also claims 'powered by Fliggy (Alibaba Group)' while all runtime instructions use an npm package named @fly-ai/flyai-cli — there is no homepage, source repo, or explanation of how Fliggy is involved. The vendor/branding mismatch and lack of source attribution are unexplained.
Instruction Scope
All runtime activity is confined to calling the flyai CLI and formatting results. The instructions do not ask the agent to read arbitrary files or environment variables. They do, however, require installing a global npm package if the CLI is missing, insist every user-facing answer come from CLI output (never from training data), and instruct maintaining an internal execution log. The runbook shows possible writes to .flyai-execution-log.json, which will persist query/command data locally.
!
Install Mechanism
There is no formal install spec in the skill bundle — instead the SKILL.md tells the agent to run 'npm i -g @fly-ai/flyai-cli'. Installing a global npm package instructed by the skill is a moderate risk: npm packages can execute arbitrary code during install and the skill provides no link to review the package, no checksum, and no official homepage or release host. Because the skill forces installation before answering, this is a notable risk vector.
Credentials
The skill declares no required environment variables or credentials. That is reasonable for an instruction-only CLI-based skill, but somewhat odd because booking/real-time pricing CLIs typically require authentication. The SKILL.md does not explain how authentication with the flight service is performed (interactive login, stored tokens, or built-in anonymous API), so credential handling is unspecified.
Persistence & Privilege
always:false and no OS restrictions are fine. The runbook instructs appending an execution log to a local file (.flyai-execution-log.json) if filesystem writes are available; writing local logs is plausible for diagnostics but could store sensitive user queries or CLI output. The skill does not request or modify other skills or system-wide settings.
What to consider before installing
Before installing or invoking this skill: 1) Verify the identity and reputation of the 'flyai' npm package (@fly-ai/flyai-cli) on npm or its source repository — do not blindly run 'npm i -g' for an unknown package. 2) Ask the skill author or registry for the source/homepage and evidence of the claimed 'Fliggy' integration; the branding mismatch is unexplained. 3) Understand authentication: confirm whether the CLI requires you to sign in or provide credentials and how those credentials are stored. 4) Be aware the skill may write a local log file (.flyai-execution-log.json) containing your raw query and CLI results — avoid using it for highly sensitive queries unless you inspect the log behavior. 5) If you proceed, review the npm package's install scripts and network activity (or run it in a sandbox) before granting it global installation privileges. If any of these checks fail or the source cannot be confirmed, do not install or run the skill.

Like a lobster shell, security has layers — review code before you run it.

latestvk97edygzngk0k52meb3bpqv4en85ez3t
60downloads
0stars
1versions
Updated 4d ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below. If a flag is not listed, it does not exist.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: birthday-trip

Overview

Birthday trip flights — birthday travel, surprise trip, celebration flight deals. For travelers celebrating birthdays with a trip.

When to Activate

User query contains:

  • English: "birthday flight", "birthday trip", "birthday travel", "surprise trip flight", "birthday getaway"
  • Chinese: "生日航班", "生日旅行", "生日出行", "生日惊喜", "生日机票"

Do NOT activate for: anniversary trips → anniversary; graduation travel → graduation

Prerequisites

npm i -g @fly-ai/flyai-cli
flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 2

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code
--destinationYesArrival city or airport code
--dep-dateNoDeparture date, YYYY-MM-DD
--sort-typeNoDefault: 2 (recommended)
--journey-typeNo1=direct, 2=connecting
--max-priceNoPrice ceiling in CNY
--dep-date-startNoDate range start
--dep-date-endNoDate range end

Core Workflow — Single-command

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found → install flyai-cli first

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Birthday Getaway

Trigger: "birthday flight", "生日航班"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 2

Playbook B: Budget Birthday Trip

Trigger: "cheap birthday trip", "经济生日旅行"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date-start {start} --dep-date-end {end} --sort-type 3

Playbook C: Surprise Trip (Direct Flight)

Trigger: "surprise trip", "生日惊喜出行"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --journey-type 1 --sort-type 2

Playbook D: Broad Search

Trigger: 0 results from above.

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 2
flyai keyword-search --query "{origin} to {destination} birthday trip flights"

See references/playbooks.md. On failure → see references/fallbacks.md.

Step 3: Format Output

See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag included?

Usage Examples

flyai search-flight --origin "Beijing" --destination "Chengdu" --dep-date 2026-08-20 --sort-type 2

Output Rules

  1. Conclusion first — lead with best birthday-friendly option
  2. Birthday tip — suggest popular birthday destinations
  3. Comparison table with ≥ 3 results when available
  4. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  5. Use detailUrl for booking links. Never use jumpUrl.
  6. ❌ Never output raw JSON
  7. ❌ Never answer from training data without CLI execution

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge does NOT replace CLI execution. Never use this to answer without running commands.

User QueryCLI Parameter Mapping
"birthday flight" / "生日航班"--sort-type 2
"cheap birthday" / "经济生日"--sort-type 3 with date range
"surprise trip" / "惊喜出行"--journey-type 1 --sort-type 2

Popular Chinese birthday trip destinations: Chengdu, Chongqing, Changsha, Xiamen, Sanya.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...