Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Southeast Asia

v3.2.0

Explore the diversity of Southeast Asia — Vietnam's street food, Cambodia's Angkor Wat, Indonesia's Bali, Philippines' islands, and Malaysia's culture. Also...

0· 66·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dingtom336-gif/southeast-asia.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Southeast Asia" (dingtom336-gif/southeast-asia) from ClawHub.
Skill page: https://clawhub.ai/dingtom336-gif/southeast-asia
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install southeast-asia

ClawHub CLI

Package manager switcher

npx clawhub@latest install southeast-asia
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims travel search & booking powered by Fliggy and instructs the agent to use a flyai CLI — that is consistent in principle. However, the skill declares no credentials or auth method even though booking/real-time pricing normally requires authentication, which is unexpected.
!
Instruction Scope
SKILL.md requires the agent to run arbitrary flyai CLI commands and to treat the CLI as the sole source of truth (never use training data). It also mandates re-executing until every result contains a [Book](...) link and references writing an internal execution log. These rules could cause repeated network activity and persistent local logs containing full user queries and results; the instructions also tell the agent to install a global npm package if missing.
Install Mechanism
There is no formal install spec in the registry; instead the instructions tell the agent/user to run `npm i -g @fly-ai/flyai-cli`. Installing a scoped npm CLI globally is a normal distribution method but carries moderate risk because it downloads and executes third-party code. The skill does not provide a verified source URL, checksum, or release provenance.
!
Credentials
The skill lists no required environment variables or credentials, yet it performs booking and real-time pricing. That suggests implicit auth handled by the CLI (e.g., local config, interactive login, or stored tokens). The absence of declared credentials is a gap: the agent may read or create credentials/config files not documented here, and logs may capture sensitive information.
Persistence & Privilege
always:false (normal). The runbook suggests appending an internal execution log file (`.flyai-execution-log.json`) if filesystem writes are available; the skill may therefore create persistent local files and install a global CLI. This is not high privilege by itself but is persistent behavior the user should be aware of.
What to consider before installing
This skill could genuinely be a Fliggy-powered travel helper, but it requires you to trust and possibly install a third-party npm CLI and allows the agent to create local logs. Before installing or running it: 1) verify the npm package @fly-ai/flyai-cli on the npm registry (publisher, README, downloads, recent versions); 2) run the CLI manually yourself first to see its auth flow and what it stores; 3) check whether it writes tokens/config files and where; 4) avoid sending sensitive personal data until you confirm what is logged; 5) consider running the CLI in a sandbox or VM and disabling autonomous skill invocation if you don't want the agent to execute installs or create persistent logs automatically.

Like a lobster shell, security has layers — review code before you run it.

latestvk97bc4ca163bpybmtve6k21r9x84md0a
66downloads
0stars
1versions
Updated 2w ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI command output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: southeast-asia

Overview

Explore the diversity of Southeast Asia — Vietnam's street food, Cambodia's Angkor Wat, Indonesia's Bali, Philippines' islands, and Malaysia's culture.

When to Activate

User query contains:

  • English: "Southeast Asia", "Vietnam", "Cambodia", "Indonesia"
  • Chinese: "东南亚", "越南", "柬埔寨", "印尼", "菲律宾"

Do NOT activate for: specific: Thailand → explore-thailand

Prerequisites

npm i -g @fly-ai/flyai-cli

Parameters

This skill orchestrates multiple CLI commands. See each command's parameters below:

search-flight

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--dep-date-startNoStart of flexible date range
--dep-date-endNoEnd of flexible date range
--back-dateNoReturn date for round-trip
--sort-typeNo3 (price ascending)
--max-priceNoPrice ceiling in CNY
--journey-typeNoDefault: show both
--seat-class-nameNoCabin class (economy/business/first)
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)

Sort Options

ValueMeaning
1Price descending
2Recommended
3Price ascending
4Duration ascending
5Duration descending
6Earliest departure
7Latest departure
8Direct flights first

search-hotel

Parameters

ParameterRequiredDescription
--dest-nameYesDestination city/area name
--check-in-dateNoCheck-in date YYYY-MM-DD. Default: today
--check-out-dateNoCheck-out date. Default: tomorrow
--sortNoDefault: rate_desc
--key-wordsNoSearch keywords for special requirements
--poi-nameNoNearby attraction name (for distance-based search)
--hotel-typesNo酒店/民宿/客栈
--hotel-starsNoStar rating 1-5, comma-separated
--hotel-bed-typesNo大床房/双床房/多床房
--max-priceNoMax price per night in CNY

Sort Options

ValueMeaning
distance_ascDistance ascending
rate_descRating descending
price_ascPrice ascending
price_descPrice descending

search-poi

Parameters

ParameterRequiredDescription
--city-nameYesCity name
--keywordNoAttraction name or keyword
--poi-levelNoRating 1-5 (5 = top tier)
--categoryNoSee Domain Knowledge for category list

keyword-search

Parameters

ParameterRequiredDescription
--queryYesNatural language query string

Core Workflow — Multi-command orchestration

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: SE Asia Circuit

Trigger: "Southeast Asia trip"

Multi-country: Vietnam→Cambodia→Thailand or similar

Output: Classic SE Asia circuit.

Playbook B: Vietnam

Trigger: "Vietnam trip"

Flights + hotels in Hanoi/HCMC/Da Nang + food/heritage POIs

Output: Vietnam focused trip.

Playbook C: Philippines

Trigger: "Philippines trip"

Flights + island hotels + beach/diving POIs

Output: Philippine island hopping.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Guangzhou" --destination "Bangkok" --dep-date 2026-11-01 --sort-type 3

Output Rules

  1. Conclusion first — lead with the key finding
  2. Comparison table with ≥ 3 results when available
  3. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  4. Use detailUrl for booking links. Never use jumpUrl.
  5. ❌ Never output raw JSON
  6. ❌ Never answer from training data without CLI execution
  7. ❌ Never fabricate prices, hotel names, or attraction details

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

SE Asia visa: varies by country — Thailand (free), Vietnam (e-visa), Cambodia (visa on arrival), Indonesia (free 30 days), Philippines (free 30 days), Malaysia (free). Best season: Nov-Mar (dry). Budget: $20-50/day possible. Health: drink bottled water, mosquito protection. Top route: Bangkok→Siem Reap→Ho Chi Minh→Hanoi.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...