Luxury Escape

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill requires the agent to perform a global installation of an external NPM package (@fly-ai/flyai-cli) and execute shell commands using parameters derived from user input, which are high-risk behaviors. Specifically, the 'fliggy-fast-search' command in SKILL.md passes a natural language query directly to the CLI, creating a potential shell injection vector. While these actions are aligned with the stated travel-planning purpose, the mandatory environment modification and broad execution permissions warrant caution.