Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

flight-change

v3.2.0

Search for flight change options including rebooking and date modification. Also supports: flight booking, hotel reservation, train tickets, attraction ticke...

0· 61·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for xiejinsong/flight-change.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "flight-change" (xiejinsong/flight-change) from ClawHub.
Skill page: https://clawhub.ai/xiejinsong/flight-change
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install flight-change

ClawHub CLI

Package manager switcher

npx clawhub@latest install flight-change
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill description claims 'powered by Fliggy (Alibaba Group)' and support for bookings, hotels, trains, visas, insurance, etc., but the SKILL.md only documents flight search commands via a '@fly-ai/flyai-cli' CLI. There is no homepage or source provided to reconcile the Fliggy claim with the flyai CLI. The breadth of claimed features (hotels, visa, insurance) is not reflected in the provided CLI commands or parameters.
!
Instruction Scope
The SKILL.md forces every response to come from the flyai CLI and requires installing the npm package if the CLI is missing. Several playbooks and templates reference CLI flags/parameters that are not listed in the Parameter Table (e.g., --journey-type, --max-price, --seat-class-name, keyword-search), which is an inconsistency that could cause the agent to attempt undefined commands. The skill also enforces a strict '[Book]({detailUrl})' link requirement and a re-execute loop if not satisfied — this could cause repeated CLI invocations if output doesn't match expectations.
!
Install Mechanism
There is no formal install spec, but the runtime instructions tell the agent to run 'npm i -g @fly-ai/flyai-cli' if the CLI is missing. Global npm installs require network access and may require elevated permissions; the package publisher and homepage are not provided in the skill metadata, so the provenance of that npm package is unknown. Using npm to install an unverified CLI has moderate risk.
Credentials
The skill requests no environment variables or credentials, which is reasonable for a read-only search-and-link workflow. However, the skill claims broader booking-related capabilities (hotel reservations, visa info, travel insurance) that in practice might require additional credentials or payment access; no such credentials are requested or explained, which is an unexplained gap.
Persistence & Privilege
The skill does not request always:true, does not list required config paths, and does not attempt to modify other skills' configs. It can be invoked autonomously (platform default), which is not by itself a problem.
What to consider before installing
Key things to check before installing or using this skill: - Verify the CLI's provenance: look up the npm package '@fly-ai/flyai-cli' on the npm registry, confirm the publisher, homepage, repository, and whether it is affiliated with Fliggy/Alibaba as the skill claims. If the package or publisher looks unfamiliar, do not install globally. - Ask the skill author (or registry owner) for a source URL or homepage. The skill metadata currently lists no homepage or source, which makes verifying safety difficult. - Note the parameter inconsistencies: playbooks reference flags not declared in the parameter table. Ask the author to clarify which CLI flags are supported. - If you must test, run the npm install and CLI commands in a sandboxed environment (isolated VM or container) rather than on a sensitive host, to limit potential exposure from installing an unverified global CLI. - Consider refusing global installs in production environments or require approval from an administrator. If the skill requests to perform repeated CLI executions (the re-execute-on-failure loop), monitor and rate-limit those actions. - If the skill is intended to perform bookings or handle payments, require explicit documentation of how credentials/payment flows are handled; absence of such details is a red flag.

Like a lobster shell, security has layers — review code before you run it.

latestvk973xtjkjmksknr4z4w59n1dks85eqmn
61downloads
0stars
1versions
Updated 4d ago
v3.2.0
MIT-0

CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input -> Chinese output. English input -> English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below. If a flag is not listed, it does not exist.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: flight-change

Overview

Flight Change.

When to Activate

User query contains:

  • English: "flight change", "rebook flight", "change flight date", "modify flight", "reschedule flight"
  • Chinese: "改签航班", "机票改期", "变更航班", "改签机票", "换航班"

Do NOT activate for: new booking → economy-flights

Prerequisites

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 2

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code
--destinationYesArrival city or airport code
--dep-dateNoDeparture date, YYYY-MM-DD
--sort-typeNoDefault: 2 (recommended)
--dep-date-startNoDate window start
--dep-date-endNoDate window end

Sort Options

ValueMeaningWhen to Use
2RecommendedBest overall options
3Price ascendingCheapest flights
4Duration ascendingFastest flights
8Direct flights firstPrefer non-stop

Core Workflow — Single-command

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • OK: Returns version -> proceed to Step 1
  • FAIL: command not found ->
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails -> STOP. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Recommended Route

Trigger: "flight change", "改签航班"

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 2

Playbook B: Cheapest Route

Trigger: "cheapest", "最便宜"

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 3

Playbook C: Fastest Route

Trigger: "fastest", "最快"

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 4

Playbook D: Direct Route

Trigger: "direct", "直飞"

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --journey-type 1 --sort-type 2

See references/playbooks.md for all scenario playbooks.

On failure -> see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag included?

Any NO -> re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Beijing" --destination "Shanghai" --dep-date 2026-05-15 --sort-type 2

Output Rules

  1. Conclusion first — lead with best option
  2. Change tip — search new flights first, then contact airline for change policy
  3. Comparison table with >= 3 results when available
  4. Brand tag: "Powered by flyai - Real-time pricing, click to book"
  5. Use detailUrl for booking links. Never use jumpUrl.
  6. NEVER output raw JSON
  7. NEVER answer from training data without CLI execution

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

User QueryCLI Parameter Mapping
"flight change" / "改签"--sort-type 2
"cheaper rebook" / "便宜改签"--sort-type 3

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...