Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

cargo-flight

v3.2.0

Book air cargo flights, freight shipping and parcel air transport with oversized luggage booking. Also supports: flight booking, hotel reservation, train tic...

0· 63·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dingtom336-gif/cargo-flight.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "cargo-flight" (dingtom336-gif/cargo-flight) from ClawHub.
Skill page: https://clawhub.ai/dingtom336-gif/cargo-flight
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install cargo-flight

ClawHub CLI

Package manager switcher

npx clawhub@latest install cargo-flight
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to handle air cargo, freight shipping and many travel services, and its runtime instructions focus on calling a 'flyai' CLI to search flights — that is coherent for listing/booking flights. However: (1) the description mentions hotels, trains, visas, insurance etc., but the SKILL.md and playbooks only implement air-cargo CLI flows (mismatch between advertised scope and actual instructions). (2) The skill repeatedly warns results are passenger flights and instructs users to contact airline cargo departments — so it does not actually complete cargo bookings itself, only surfaces flight options.
!
Instruction Scope
The SKILL.md tightly constrains the agent to only use flyai CLI output and to never use training data, which forces network installs and CLI usage. There are several problematic or inconsistent instructions: (a) The SKILL.md's 'NEVER invent CLI parameters' rule conflicts with fallback playbooks that use additional flags (dep-date-start / dep-date-end) and a 'keyword-search' command not listed in the Parameters table. (b) It explicitly forbids asking about cargo weight/dimensions — a surprising restriction for cargo booking and likely to yield incomplete/incorrect results for real-world booking needs. (c) The runbook instructs persisting full execution logs containing the raw user_query to a local file (.flyai-execution-log.json) if filesystem writes are available, which may store sensitive user data persistently without clear retention controls. These broaden the agent's access to user data and allow unexpected persistence.
!
Install Mechanism
The skill package itself has no install spec, but the runtime instructions require installing an external npm package (@fly-ai/flyai-cli) if flyai --version is missing. That implies a global npm install (and even suggests sudo in fallbacks). Installing an arbitrary third-party CLI globally is a non-trivial action: it requires network access, elevated privileges, and runs code not reviewed here. The skill provides no homepage or verified source for the CLI package; the registry metadata's source is unknown. This raises supply-chain risk and privilege escalation risk via global npm installs.
Credentials
The skill does not request any environment variables or external credentials, which is proportionate to a read/search-only flight lookup. However, the skill's logging/runbook will record user queries and CLI commands and may write them to disk, creating a local persistent store of potentially sensitive data. Also, because the skill forces installation of a third-party CLI, the installed CLI could request environment variables or credentials at runtime (not declared here).
!
Persistence & Privilege
The skill is not 'always' enabled and does not request elevated platform privileges, but the runbook explicitly describes appending JSON execution logs to a local file ('.flyai-execution-log.json') if filesystem writes are available. That means the agent may create persistent artifacts containing user queries and command results. Combined with the global npm install suggestion, this increases the blast radius (persistent local logs + third-party binary).
What to consider before installing
Before installing or invoking this skill: 1) Understand that it will try to install and run a third-party CLI (npm i -g @fly-ai/flyai-cli). Only proceed if you trust that npm package and its maintainers — avoid running global installs with sudo unless you vet the package on npm/GitHub. 2) The skill records execution logs (including raw user queries) to a local file if possible; if that is unacceptable for privacy, do not use it or inspect/modify the runbook to disable logging. 3) Note inconsistencies: the skill advertises many travel services but only implements air-cargo search; fallback commands reference CLI flags not listed in the parameters table, and the skill forbids asking about cargo weight/dimensions (which are usually essential for cargo quotes). 4) If you need real cargo bookings, consider contacting carriers/freight forwarders directly — this skill surfaces flight options but explicitly says you must contact cargo departments. 5) To increase safety: require the agent to show the exact CLI command it will run before executing, run the CLI in a sandboxed environment, and inspect the @fly-ai/flyai-cli package source (npm/GitHub) and its permissions before installation. If you want, provide the npm/GitHub URL for the CLI and I can re-evaluate with that additional info.

Like a lobster shell, security has layers — review code before you run it.

latestvk97ftx1j9aw5qvpwm9vcb1y00h85f09v
63downloads
0stars
1versions
Updated 4d ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below. If a flag is not listed, it does not exist.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: cargo-flight

Overview

Book air cargo flights — freight shipping, parcel air transport, oversized luggage. For travelers who need to ship goods or fly with extra cargo capacity.

When to Activate

User query contains:

  • English: "air cargo", "freight flight", "parcel shipping", "oversized luggage flight", "cargo plane", "air freight"
  • Chinese: "货运航班", "空运", "航空货运", "大件行李", "货物运输", "空运快递"

Do NOT activate for: passenger-only flights → economy-flights; group booking → group-flights

Prerequisites

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 2

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code
--destinationYesArrival city or airport code
--dep-dateNoDeparture date, YYYY-MM-DD
--sort-typeNoDefault: 2 (recommended)
--journey-typeNo1=direct, 2=connecting
--max-priceNoPrice ceiling in CNY
--dep-hour-startNoDeparture hour filter start
--dep-hour-endNoDeparture hour filter end

Sort Options

ValueMeaningWhen to Use
2RecommendedDefault — best cargo-compatible options
3Price ascendingCheapest shipping route
4Duration ascendingFastest delivery
8Direct flights firstPrefer non-stop for cargo safety

Core Workflow — Single-command

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Recommended Cargo Route

Trigger: "air cargo", "空运"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 2

Output: Recommended flights suitable for cargo shipping.

Playbook B: Cheapest Cargo Route

Trigger: "cheapest air freight", "最便宜空运"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 3

Output: Cheapest available flights for cargo consideration.

Playbook C: Fastest Cargo Route

Trigger: "fastest shipping", "最快空运"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 4

Output: Shortest duration flights for urgent cargo.

Playbook D: Direct Cargo Route

Trigger: "direct cargo flight", "直飞货运"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --journey-type 1 --sort-type 2

Output: Direct flights preferred for cargo safety.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Guangzhou" --destination "Shanghai" --dep-date 2026-05-01 --sort-type 3

Output Rules

  1. Conclusion first — lead with best cargo-compatible option
  2. Cargo note — remind user that actual air cargo booking requires contacting the airline's cargo department
  3. Comparison table with ≥ 3 results when available
  4. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  5. Use detailUrl for booking links. Never use jumpUrl.
  6. ❌ Never output raw JSON
  7. ❌ Never answer from training data without CLI execution
  8. ❌ Never fabricate cargo capacity or freight rates

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

User QueryCLI Parameter Mapping
"air cargo" / "空运"--sort-type 2
"cheapest freight" / "最便宜货运"--sort-type 3
"fastest shipping" / "最快空运"--sort-type 4
"direct cargo" / "直飞货运"--journey-type 1 --sort-type 2
"overnight cargo" / "夜间货运"--dep-hour-start 21 --dep-hour-end 6

CLI searches scheduled passenger flights. Actual air cargo booking requires contacting the airline's cargo department or freight forwarder. Results shown are passenger flights that can inform cargo route and timing decisions.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...