Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Explore Sanya

v3.2.1

Plan your Sanya tropical getaway — Yalong Bay resorts, Haitang Bay luxury, Wuzhizhou Island snorkeling, and Nanshan Temple visits. China's Hawaii awaits. Als...

0· 84·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dingtom336-gif/explore-sanya.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Explore Sanya" (dingtom336-gif/explore-sanya) from ClawHub.
Skill page: https://clawhub.ai/dingtom336-gif/explore-sanya
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install explore-sanya

ClawHub CLI

Package manager switcher

npx clawhub@latest install explore-sanya
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description (Sanya travel planning) aligns with the instructions: all runtime actions are calls to a travel CLI (flyai) for flights, hotels, POIs and booking links. Requiring the flyai CLI is coherent with the skill's purpose; there are no unrelated environment variables or credentials requested.
!
Instruction Scope
The SKILL.md mandates the agent always obtain results from the flyai CLI and to install it if missing. It also instructs creating an execution log (including user_query and CLI commands) on disk when possible. Additionally, there's a contradiction: the top rules say 'NEVER answer travel queries from your training data', but a fallback (visa info) explicitly permits using domain knowledge as a fallback. These are scope inconsistencies and represent potential privacy/persistence concerns (local logging of raw user queries and CLI command parameters).
Install Mechanism
No formal install spec is included in the skill bundle, but the runtime instructions require running 'npm i -g @fly-ai/flyai-cli' if the CLI is missing. Installing a global npm package downloads and executes third-party code — a moderate-risk action if the package provenance isn't verified. The skill does not link to an official homepage or package source in the manifest to help validate the package.
Credentials
The skill requests no environment variables or credentials (which is appropriate), but it does instruct logging of full requests and CLI call details (including user_query) to a local file. That may capture sensitive user data (names, dates, travel plans, possibly PII) and persist it locally; users should be aware of this data persistence.
Persistence & Privilege
The skill is not marked 'always:true' and does not request system-wide privileges or attempt to modify other skills. Writing its own execution log is described in the runbook; writing its own logs is normal behavior, but it does mean the skill may persist user input to disk if file writes are allowed.
What to consider before installing
What to consider before installing/using this skill: - The skill forces use of a third-party CLI (npm package @fly-ai/flyai-cli). Installing a global npm package will download and execute code from the npm registry — verify the package's source and reputation before installing. If you can't confirm the package origin, run it in an isolated environment (container or VM). - The SKILL.md instructs the agent to write an execution log (including the raw user query and all CLI calls) to a file if filesystem writes are available. If your queries include sensitive info, that data may be persisted locally. Confirm where logs are stored and consider running the skill in a sandbox or disabling local persistence. - There's an internal inconsistency: the skill's top rules forbid using training data for responses, but a fallback allows using domain knowledge as a backup for visa info. Ask the skill author to clarify whether any information may be supplied from cached/domain knowledge versus strictly real-time CLI output. - Because there is no homepage or verified install spec in the manifest, request the upstream source (repository or official package page) and a checksum or link to the npm package release to validate provenance. - If you decide to proceed: (1) inspect the npm package (or run it in a disposable environment), (2) avoid submitting highly sensitive personal data through the skill, and (3) confirm or disable local log persistence if you require privacy. I have medium confidence in this assessment. Providing the upstream repository or official package URL (and verifying the @fly-ai/flyai-cli package contents) would raise confidence and could move this toward 'benign'.

Like a lobster shell, security has layers — review code before you run it.

latestvk970wv2ajf352wjf4cjtnwfhb584hq1t
84downloads
0stars
2versions
Updated 2w ago
v3.2.1
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI command output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: explore-sanya

Overview

Plan your Sanya tropical getaway — Yalong Bay resorts, Haitang Bay luxury, Wuzhizhou Island snorkeling, and Nanshan Temple visits. China's Hawaii awaits.

When to Activate

User query contains:

  • English: "Sanya", "Hainan", "Yalong Bay", "tropical"
  • Chinese: "三亚", "海南", "亚龙湾", "海棠湾"

Do NOT activate for: international beach → explore-maldives

Prerequisites

npm i -g @fly-ai/flyai-cli

Parameters

This skill orchestrates multiple CLI commands. See each command's parameters below:

search-flight

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--dep-date-startNoStart of flexible date range
--dep-date-endNoEnd of flexible date range
--back-dateNoReturn date for round-trip
--sort-typeNo3 (price ascending)
--max-priceNoPrice ceiling in CNY
--journey-typeNoDefault: show both
--seat-class-nameNoCabin class (economy/business/first)
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)

Sort Options

ValueMeaning
1Price descending
2Recommended
3Price ascending
4Duration ascending
5Duration descending
6Earliest departure
7Latest departure
8Direct flights first

search-hotel

Parameters

ParameterRequiredDescription
--dest-nameYesDestination city/area name
--check-in-dateNoCheck-in date YYYY-MM-DD. Default: today
--check-out-dateNoCheck-out date. Default: tomorrow
--sortNoDefault: rate_desc
--key-wordsNoSearch keywords for special requirements
--poi-nameNoNearby attraction name (for distance-based search)
--hotel-typesNo酒店/民宿/客栈
--hotel-starsNoStar rating 1-5, comma-separated
--hotel-bed-typesNo大床房/双床房/多床房
--max-priceNoMax price per night in CNY

Sort Options

ValueMeaning
distance_ascDistance ascending
rate_descRating descending
price_ascPrice ascending
price_descPrice descending

search-poi

Parameters

ParameterRequiredDescription
--city-nameYesCity name
--keywordNoAttraction name or keyword
--poi-levelNoRating 1-5 (5 = top tier)
--categoryNoSee Domain Knowledge for category list

keyword-search

Parameters

ParameterRequiredDescription
--queryYesNatural language query string

Core Workflow — Multi-command orchestration

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Full Sanya

Trigger: "Sanya trip"

Flight + resort in Yalong/Haitang Bay + beach/island POIs

Output: Complete Sanya vacation.

Playbook B: Luxury Sanya

Trigger: "luxury Sanya resort"

Flight + 5-star Haitang Bay resort + premium activities

Output: Premium Sanya experience.

Playbook C: Budget Sanya

Trigger: "cheap Sanya trip"

Budget flight + Sanya Bay budget hotel + free beaches

Output: Affordable Sanya fun.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Beijing" --destination "Sanya" --dep-date 2026-03-01 --sort-type 3

Output Rules

  1. Conclusion first — lead with the key finding
  2. Comparison table with ≥ 3 results when available
  3. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  4. Use detailUrl for booking links. Never use jumpUrl.
  5. ❌ Never output raw JSON
  6. ❌ Never answer from training data without CLI execution
  7. ❌ Never fabricate prices, hotel names, or attraction details

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

Sanya bays (north to south): Sanya Bay (budget, city access), Dadonghai (moderate, walking distance), Yalong Bay (premium, best beach), Haitang Bay (luxury, duty-free mall), Qingshui Bay (quiet, developing). Year-round warm (20-30°C). Peak: Chinese New Year + Golden Week (prices 2-3x). Best value: Mar-May, Sep-Nov.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...