Back to skill

Security audit

国内航班查询

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do the advertised domestic flight search, but users should expect their route, date, and query text to be sent through an external proxy service.

Install only if you are comfortable sending domestic flight search details, such as cities, dates, filters, and any natural-language query text, through the skill publisher's cloud proxy to retrieve Fliggy results. Avoid putting unrelated personal information into flight queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill sends user flight queries, including origin, destination, dates, and free-form natural-language travel requests, to an external proxy service without any visible user-facing notice or consent mechanism in the code. Travel queries can reveal sensitive itinerary and location information, so undisclosed third-party transmission creates a privacy and data-handling risk even if transport is over HTTPS.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.