Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Week Trip

v3.2.0

Plan an epic 7-day vacation — multi-city routes, intercity transportation, hotel transitions, and balanced daily itineraries for a full week of adventure. Al...

0· 67·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for xiejinsong/week-trip.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Week Trip" (xiejinsong/week-trip) from ClawHub.
Skill page: https://clawhub.ai/xiejinsong/week-trip
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install week-trip

ClawHub CLI

Package manager switcher

npx clawhub@latest install week-trip
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to plan week-long trips and instructs the agent to use the flyai CLI for flights, hotels, POI searches and booking links. Requiring a booking-capable CLI is coherent with the stated purpose.
!
Instruction Scope
SKILL.md requires the agent to: (a) rely exclusively on flyai CLI output (never use model knowledge), (b) auto-install the @fly-ai/flyai-cli if missing, and (c) enforce every result include a [Book](...) link. The runbook also instructs writing a persistent execution log (.flyai-execution-log.json) containing raw user_query and steps if file system writes are available. Persisting user queries and CLI results is outside the explicit skill metadata and can capture sensitive input. The self-test/re-execute loop requirement increases the chance of repeated network calls/installs if outputs don't match the strict template.
Install Mechanism
There is no formal install spec in the registry metadata, but the skill's runtime instructions mandate npm i -g @fly-ai/flyai-cli. Installing a global npm package at runtime causes third-party code to be downloaded and run on the host (moderate risk). The package name is a normal npm-style install (traceable) rather than an arbitrary URL, but automatic global installs should be treated cautiously and ideally require explicit user approval.
Credentials
The skill declares no required environment variables or credentials, which is reasonable for a read-only planner that returns booking links. However, the runbook's log schema includes request_id, user_query and other fields that may contain sensitive info; these are not declared as persisted artifacts. Also, the skill claims booking/reservation capability but does not request payment/auth credentials — it appears to rely on external booking links rather than performing bookings itself (this is plausible but worth confirming).
!
Persistence & Privilege
The skill's runbook explicitly recommends appending an execution log to .flyai-execution-log.json if filesystem writes are available. That creates persistent local records of user queries, CLI commands, and results. This persistent logging behavior is not described in the registry metadata and could retain sensitive user input. The skill does not request elevated platform privileges, but local persistence without explicit user consent is a notable privacy concern.
What to consider before installing
This skill is coherent with travel planning but contains two operational risks you should weigh before installing: (1) it will auto-install and invoke a third‑party npm CLI (@fly-ai/flyai-cli) if that binary is missing — installing global npm packages runs unreviewed code from the npm registry and may require elevated permissions; (2) it suggests writing a persistent execution log (.flyai-execution-log.json) containing user queries and CLI outputs to disk. Before installing, consider: - Do you trust the @fly-ai/flyai-cli package and its publisher? Check the package page, source repo, and recent maintainer activity. - Run the CLI in a sandbox or ask for an option to decline auto-install; prefer manual installation with consent. - Confirm whether persistent logs will be created and where; if unwanted, run the skill in an environment where filesystem writes are blocked or review the skill to remove the logging step. - Be aware the skill forces strict reliance on real‑time CLI results and may re-run commands until output matches a template, which can increase network activity. If you want, I can list specific questions to ask the skill author or suggest a safer workflow (e.g., run the CLI yourself and paste results) to avoid automatic installs and local persistence.

Like a lobster shell, security has layers — review code before you run it.

latestvk97d1sty30y2yh7ge2e8k67jm184p3js
67downloads
0stars
1versions
Updated 2w ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI command output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: week-trip

Overview

Plan an epic 7-day vacation — multi-city routes, intercity transportation, hotel transitions, and balanced daily itineraries for a full week of adventure.

When to Activate

User query contains:

  • English: "one week", "7 days", "week-long vacation", "week trip"
  • Chinese: "一周旅行", "7天行程", "一周假期"

Do NOT activate for: weekend → weekend-trip

Prerequisites

npm i -g @fly-ai/flyai-cli

Parameters

This skill orchestrates multiple CLI commands. See each command's parameters below:

search-flight

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--dep-date-startNoStart of flexible date range
--dep-date-endNoEnd of flexible date range
--back-dateNoReturn date for round-trip
--sort-typeNo3 (price ascending)
--max-priceNoPrice ceiling in CNY
--journey-typeNoDefault: show both
--seat-class-nameNoCabin class (economy/business/first)
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)

Sort Options

ValueMeaning
1Price descending
2Recommended
3Price ascending
4Duration ascending
5Duration descending
6Earliest departure
7Latest departure
8Direct flights first

search-hotel

Parameters

ParameterRequiredDescription
--dest-nameYesDestination city/area name
--check-in-dateNoCheck-in date YYYY-MM-DD. Default: today
--check-out-dateNoCheck-out date. Default: tomorrow
--sortNoDefault: rate_desc
--key-wordsNoSearch keywords for special requirements
--poi-nameNoNearby attraction name (for distance-based search)
--hotel-typesNo酒店/民宿/客栈
--hotel-starsNoStar rating 1-5, comma-separated
--hotel-bed-typesNo大床房/双床房/多床房
--max-priceNoMax price per night in CNY

Sort Options

ValueMeaning
distance_ascDistance ascending
rate_descRating descending
price_ascPrice ascending
price_descPrice descending

search-poi

Parameters

ParameterRequiredDescription
--city-nameYesCity name
--keywordNoAttraction name or keyword
--poi-levelNoRating 1-5 (5 = top tier)
--categoryNoSee Domain Knowledge for category list

keyword-search

Parameters

ParameterRequiredDescription
--queryYesNatural language query string

Core Workflow — Multi-command orchestration

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Multi-City Week

Trigger: "week in Japan"

Full 4-command orchestration across 2-3 cities, with intercity transport

Output: 7-day multi-city with transport.

Playbook B: Single-City Deep

Trigger: "one week in Bangkok"

Flight + 7-night hotel + multiple POI category searches

Output: Deep dive single city for a week.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

Full orchestration example with 3 cities over 7 days

Output Rules

  1. Conclusion first — lead with the key finding
  2. Comparison table with ≥ 3 results when available
  3. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  4. Use detailUrl for booking links. Never use jumpUrl.
  5. ❌ Never output raw JSON
  6. ❌ Never answer from training data without CLI execution
  7. ❌ Never fabricate prices, hotel names, or attraction details

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

Week-long planning: split into 2-3 city segments (3+4 or 2+3+2 days). Use overnight trains or morning flights for intercity (saves a hotel night). Midway hotel switch is tiring — minimize to 1-2 times. Build in one 'free day' without plans for rest and spontaneity.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...