Luxury Escape
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill requires the agent to perform a global installation of an external NPM package (@fly-ai/flyai-cli) and execute shell commands using parameters derived from user input, which are high-risk behaviors. Specifically, the 'fliggy-fast-search' command in SKILL.md passes a natural language query directly to the CLI, creating a potential shell injection vector. While these actions are aligned with the stated travel-planning purpose, the mandatory environment modification and broad execution permissions warrant caution.
