Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Plan Weekend Trips — Short Getaways, Weekend Flights, 2-Day Hotel Deals & Mini Vacations

v3.2.0

Plan the perfect 2-day weekend escape to nearby destinations — auto-suggests places within 2-3 hours that maximize your short break. Also supports: flight bo...

0· 46·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims real-time flight/hotel/POI results and mandates using a flyai CLI for every answer — that aligns with needing a live data client. However, there is no homepage or source link for the skill or the @fly-ai/flyai-cli package, which leaves the provenance of the required client unclear.
!
Instruction Scope
Runtime instructions strictly require installing and invoking the flyai CLI and forbid using any training-data fallback. The runbook also instructs the agent to append an execution log to .flyai-execution-log.json if filesystem writes are available — this creates persistent data on disk (request/response logs) which may include user queries and should be disclosed to users.
!
Install Mechanism
Although the skill itself has no install spec, it instructs the agent to run npm i -g @fly-ai/flyai-cli if flyai is missing. Installing a global npm package is a supply-chain risk (postinstall scripts, arbitrary code). No trusted source or homepage for the CLI package is provided to verify authenticity.
Credentials
The skill declares no required environment variables or credentials, which looks minimal and appropriate. However, a real booking CLI often requires authentication or token configuration; the SKILL.md does not explain where or how flyai obtains credentials (interactive login, local config, environment variables), so credential handling is unclear.
!
Persistence & Privilege
always:false (good) and autonomous invocation is normal, but the runbook explicitly instructs appending execution logs to a local file (.flyai-execution-log.json) when filesystem writes are available. Combined with the global npm install, this creates persistent artifacts and modest privilege/persistence on the host.
What to consider before installing
Before installing or using this skill, verify the flyai client and the skill author: 1) Ask the skill owner for a homepage or source repo and confirm the @fly-ai/flyai-cli package on the npm registry (npmjs.com) — check publisher, versions, and download counts. 2) Inspect the package (or view its repository) for postinstall scripts or unusual permissions; prefer not to run a global npm install until you vet it. 3) Ask how flyai authenticates and where any tokens are stored; confirm it will not exfiltrate credentials. 4) Be aware the skill will append an execution log (.flyai-execution-log.json) to the working directory if writes are available — ask what data is logged and where it is stored/rotated. 5) If you want to test safely, run the CLI in an isolated environment (VM/container) or install it locally (not -g), and run npm audit / review package.json for scripts. If provenance or authentication handling is unclear or the package cannot be verified, avoid installing the CLI and decline to use the skill.

Like a lobster shell, security has layers — review code before you run it.

latestvk976cj6b1g6rgbmc5tk2de340584rvvh
46downloads
0stars
1versions
Updated 5d ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI command output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: weekend-trip

Overview

Plan the perfect 2-day weekend escape to nearby destinations — auto-suggests places within 2-3 hours that maximize your short break.

When to Activate

User query contains:

  • English: "weekend trip", "short break", "weekend getaway", "2 days"
  • Chinese: "周末去哪", "短途游", "周末出发", "两天一夜"

Do NOT activate for: longer trip → three-day-trip

Prerequisites

npm i -g @fly-ai/flyai-cli

Parameters

This skill orchestrates multiple CLI commands. See each command's parameters below:

search-flight

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--dep-date-startNoStart of flexible date range
--dep-date-endNoEnd of flexible date range
--back-dateNoReturn date for round-trip
--sort-typeNo3 (price ascending)
--max-priceNoPrice ceiling in CNY
--journey-typeNoDefault: show both
--seat-class-nameNoCabin class (economy/business/first)
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)

Sort Options

ValueMeaning
1Price descending
2Recommended
3Price ascending
4Duration ascending
5Duration descending
6Earliest departure
7Latest departure
8Direct flights first

search-hotel

Parameters

ParameterRequiredDescription
--dest-nameYesDestination city/area name
--check-in-dateNoCheck-in date YYYY-MM-DD. Default: today
--check-out-dateNoCheck-out date. Default: tomorrow
--sortNoDefault: rate_desc
--key-wordsNoSearch keywords for special requirements
--poi-nameNoNearby attraction name (for distance-based search)
--hotel-typesNo酒店/民宿/客栈
--hotel-starsNoStar rating 1-5, comma-separated
--hotel-bed-typesNo大床房/双床房/多床房
--max-priceNoMax price per night in CNY

Sort Options

ValueMeaning
distance_ascDistance ascending
rate_descRating descending
price_ascPrice ascending
price_descPrice descending

search-poi

Parameters

ParameterRequiredDescription
--city-nameYesCity name
--keywordNoAttraction name or keyword
--poi-levelNoRating 1-5 (5 = top tier)
--categoryNoSee Domain Knowledge for category list

keyword-search

Parameters

ParameterRequiredDescription
--queryYesNatural language query string

Core Workflow — Multi-command orchestration

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Weekend Auto-Plan

Trigger: "周末去哪玩"

flyai search-flight --origin "{o}" --destination "{nearby}" --dep-date {fri} --back-date {sun} --sort-type 3
flyai search-hotel --dest-name "{nearby}" --check-in-date {fri} --check-out-date {sun} --sort rate_desc
flyai search-poi --city-name "{nearby}" --poi-level 5

Output: Auto-plan nearby weekend.

Playbook B: Budget Weekend

Trigger: "cheap weekend escape"

flyai search-flight --origin "{o}" --destination "{nearby}" --dep-date {fri} --back-date {sun} --sort-type 3
flyai search-hotel --dest-name "{nearby}" --sort price_asc --check-in-date {fri} --check-out-date {sun}

Output: Budget-friendly weekend.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Shanghai" --destination "Hangzhou" --dep-date 2026-05-02 --back-date 2026-05-04 --sort-type 3

Output Rules

  1. Conclusion first — lead with the key finding
  2. Comparison table with ≥ 3 results when available
  3. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  4. Use detailUrl for booking links. Never use jumpUrl.
  5. ❌ Never output raw JSON
  6. ❌ Never answer from training data without CLI execution
  7. ❌ Never fabricate prices, hotel names, or attraction details

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

Weekend escape radius: 1-3h flight or 1-2h high-speed rail. From Shanghai: Hangzhou, Suzhou, Nanjing, Sanya. From Beijing: Qingdao, Dalian, Xi'an. From Guangzhou: Xiamen, Guilin, Sanya. Key: depart Friday evening, return Sunday. Book Tue for best weekend prices.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...