Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Explore Korea

v3.2.0

Plan your Korea experience — Seoul's palaces and K-pop culture, Busan's beaches, Jeju Island's nature, Korean BBQ crawls, and K-beauty shopping. Also support...

0· 79·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for xiejinsong/explore-korea.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Explore Korea" (xiejinsong/explore-korea) from ClawHub.
Skill page: https://clawhub.ai/xiejinsong/explore-korea
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install explore-korea

ClawHub CLI

Package manager switcher

npx clawhub@latest install explore-korea
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to plan Korea travel and to be 'Powered by Fliggy', and its runtime instructions consistently call a flyai CLI. Requiring a CLI to fetch real-time booking data is coherent for a travel skill, but the manifest lacks any declared install or source and the branding ('Fliggy') does not match the CLI name ('flyai' / @fly-ai/flyai-cli), which is an unexplained inconsistency worth questioning.
!
Instruction Scope
The SKILL.md mandates that every answer must come exclusively from the flyai CLI (never use training data) and includes a 'self-test' that forces re-execution until a [Book](...) link is present — this could cause repeated external calls or loops. The runbook instructs writing an execution log to .flyai-execution-log.json containing full user_query and CLI calls; that persists potentially sensitive user input locally. The skill also instructs automatic installation if the CLI is missing, which expands runtime actions beyond mere queries.
Install Mechanism
There is no registry install spec; the SKILL.md tells the agent to run 'npm i -g @fly-ai/flyai-cli' if flyai isn't present. A global npm install is a moderate-risk action (it will write code to disk and run code from the npm registry). That is arguably necessary for a CLI-driven skill, but because the skill package source and trustworthiness are not declared, this is an area to verify before proceeding.
Credentials
The skill requests no environment variables or credentials in the registry metadata (good). However, the flyai CLI itself may require or use credentials or perform network I/O; the skill does not document how CLI authentication works. Also, the runbook's persistent execution log will record user queries and CLI commands, which could include sensitive details — the skill does not describe log retention or encryption.
Persistence & Privilege
The skill is not always-enabled and does not request elevated platform privileges. However it instructs creating and appending to a local file (.flyai-execution-log.json) if filesystem writes are available, which gives it persistent artifacts on disk containing user queries and call metadata. This is within the skill's scope but increases persistent exposure of data.
What to consider before installing
This skill is plausible for real-time travel planning but has a few red flags to verify before installing or enabling it: - Confirm the CLI package: look up @fly-ai/flyai-cli on the npm registry (author, homepage, recent versions, and trust signals). Installing a global npm package runs third-party code on your system. - Ask the publisher why the skill says 'Powered by Fliggy' but uses a 'flyai' CLI — clarify the actual backend/service and where data is sent. - Expect the skill to perform network I/O and possibly require CLI authentication; ask how credentials are handled and whether any secrets will be stored. - The runbook writes .flyai-execution-log.json with user_query and CLI call logs. If you care about sensitive queries, run this skill only in an isolated environment or after modifying the runbook behavior. - The 'self-test' rule (re-execute until a [Book](...) link appears) could cause repeated calls; watch for unexpected network traffic or repeated bookings attempts. If you decide to proceed: manually inspect the flyai-cli package first, prefer manual (not automatic) installation, run the CLI in a sandbox/container, and verify network endpoints and auth behavior. If any of these clarifications are unavailable, treat the skill cautiously or prefer a travel skill with transparent source code and declared install metadata.

Like a lobster shell, security has layers — review code before you run it.

latestvk971sr01vje47xy28wm3zf77yh84gdmv
79downloads
0stars
2versions
Updated 2w ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI command output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: explore-korea

Overview

Plan your Korea experience — Seoul's palaces and K-pop culture, Busan's beaches, Jeju Island's nature, Korean BBQ crawls, and K-beauty shopping.

When to Activate

User query contains:

  • English: "Korea", "Seoul", "Busan", "Jeju"
  • Chinese: "韩国", "首尔", "釜山", "济州岛", "去韩国"

Do NOT activate for: Japan → explore-japan

Prerequisites

npm i -g @fly-ai/flyai-cli

Parameters

This skill orchestrates multiple CLI commands. See each command's parameters below:

search-flight

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--dep-date-startNoStart of flexible date range
--dep-date-endNoEnd of flexible date range
--back-dateNoReturn date for round-trip
--sort-typeNo3 (price ascending)
--max-priceNoPrice ceiling in CNY
--journey-typeNoDefault: show both
--seat-class-nameNoCabin class (economy/business/first)
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)

Sort Options

ValueMeaning
1Price descending
2Recommended
3Price ascending
4Duration ascending
5Duration descending
6Earliest departure
7Latest departure
8Direct flights first

search-hotel

Parameters

ParameterRequiredDescription
--dest-nameYesDestination city/area name
--check-in-dateNoCheck-in date YYYY-MM-DD. Default: today
--check-out-dateNoCheck-out date. Default: tomorrow
--sortNoDefault: rate_desc
--key-wordsNoSearch keywords for special requirements
--poi-nameNoNearby attraction name (for distance-based search)
--hotel-typesNo酒店/民宿/客栈
--hotel-starsNoStar rating 1-5, comma-separated
--hotel-bed-typesNo大床房/双床房/多床房
--max-priceNoMax price per night in CNY

Sort Options

ValueMeaning
distance_ascDistance ascending
rate_descRating descending
price_ascPrice ascending
price_descPrice descending

search-poi

Parameters

ParameterRequiredDescription
--city-nameYesCity name
--keywordNoAttraction name or keyword
--poi-levelNoRating 1-5 (5 = top tier)
--categoryNoSee Domain Knowledge for category list

keyword-search

Parameters

ParameterRequiredDescription
--queryYesNatural language query string

Core Workflow — Multi-command orchestration

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Full Korea

Trigger: "Korea trip"

visa check + flights to ICN + hotels + palaces/food/shopping POIs

Output: Complete Korea itinerary.

Playbook B: Seoul

Trigger: "Seoul trip"

Flight to ICN + Seoul hotel + Gangnam/Myeongdong/palace POIs

Output: Seoul city deep dive.

Playbook C: Jeju

Trigger: "Jeju Island"

Flight to CJU + Jeju hotel + nature POIs

Output: Jeju Island nature trip.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Beijing" --destination "Seoul" --dep-date 2026-05-01 --sort-type 3

Output Rules

  1. Conclusion first — lead with the key finding
  2. Comparison table with ≥ 3 results when available
  3. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  4. Use detailUrl for booking links. Never use detailUrl.
  5. ❌ Never output raw JSON
  6. ❌ Never answer from training data without CLI execution
  7. ❌ Never fabricate prices, hotel names, or attraction details

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

Korea: visa required for Chinese citizens. Airports: ICN (Incheon, international), GMP (Gimpo, domestic+Japan/China), CJU (Jeju), PUS (Busan). T-money card for transit. Best seasons: spring (cherry blossom, Apr), autumn (foliage, Oct-Nov). Korean BBQ: order 2+ servings minimum. Shopping: Myeongdong (cosmetics), Dongdaemun (fashion).

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...