Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

military-flights

v3.2.0

Find military flight benefits, veteran discounts and armed forces travel deals with military fare tickets for service members. Also supports: flight booking,...

0· 60·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for xiejinsong/military-flights.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "military-flights" (xiejinsong/military-flights) from ClawHub.
Skill page: https://clawhub.ai/xiejinsong/military-flights
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install military-flights

ClawHub CLI

Package manager switcher

npx clawhub@latest install military-flights
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The SKILL.md repeatedly requires a 'flyai' CLI (and even instructs the agent to run 'npm i -g @fly-ai/flyai-cli' if missing), but the registry metadata claims no required binaries and provides no homepage or source. Requiring an external network-downloaded CLI is plausible for a real-time booking skill, but the omission from declared requirements and absence of publisher/homepage information is an incoherence and reduces traceability.
!
Instruction Scope
Runtime instructions mandate executing CLI commands, performing an npm global install if the CLI is absent, and strictly disallow answering from training data. The runbook also instructs persisting an execution log (.flyai-execution-log.json) that would contain the raw user_query and other runtime details. Those are legitimate for an API-backed flight skill, but they expand the agent's I/O footprint (network installs + writing potentially sensitive user queries to disk) and are not represented in metadata.
!
Install Mechanism
There is no install spec in the registry, yet SKILL.md instructs a global npm install ('npm i -g @fly-ai/flyai-cli'). Installing a package from npm is a moderate-to-high-risk action because it runs third-party code on the host; the skill gives no provenance (no homepage, no publisher identity) or verification steps (checksums, pinned version). That makes the implicit install operation higher risk than an instruction-only skill without install steps.
Credentials
The skill does not request environment variables or credentials (good), and its declared scope (find military fares) matches the need to call an external airfare service. However, the runbook persists user_query and other internal state to disk, which could capture PII or sensitive travel details. The absence of declared config paths or secrets is coherent but the logging behavior should be considered sensitive.
!
Persistence & Privilege
The skill is not marked 'always', which is appropriate, but the instructions proactively install a global npm package and suggest appending execution logs to '.flyai-execution-log.json' in the working directory. A global npm install changes system state and persistently places third-party binaries on the host; the log file creates persistent local artifacts. Both are elevated privileges relative to a purely read-only instruction skill and are not surfaced in metadata.
What to consider before installing
This skill is plausible for live military-fare lookups, but it has several red flags you should consider before installing or allowing autonomous runs: - Provenance missing: There is no homepage or source repo and the registry metadata does not declare the required 'flyai' CLI even though SKILL.md requires it. Verify the publisher identity and read the package repository (npm page / GitHub) before installing. - Implicit global install: The skill will attempt to run 'npm i -g @fly-ai/flyai-cli' if the CLI is absent. Global npm installs execute third-party code on your machine — prefer installing in a sandbox or review the package contents first. - Persistent local logs: The runbook suggests appending a JSON execution log (.flyai-execution-log.json) containing the raw user_query and steps. This may store PII/travel details. If you install, decide whether persistent logging is acceptable and where logs are written. - No declared binaries/install spec: The registry should list required binaries or an install spec. The omission is an incoherence; ask the publisher to provide a formal install manifest or signed release URLs. - Operational impact: If you allow the agent to auto-install packages, restrict it to a controlled environment or require manual confirmation. If you cannot validate the @fly-ai package, decline to install or run the skill. What would raise confidence to 'benign': a verifiable homepage or source repo, published package with a readable audit trail (repository, changelog, maintainer identity), a registry-declared required binary entry for 'flyai', and a non-global/sandboxed install path or explicit integrity checks. If you want, I can list specific steps to safely vet the npm package and run the skill in a sandboxed environment.

Like a lobster shell, security has layers — review code before you run it.

latestvk971hx7f9d9jwrvhhhb76p73m585epze
60downloads
0stars
1versions
Updated 4d ago
v3.2.0
MIT-0

⚠️ CRITICAL EXECUTION RULES

You are a CLI executor, NOT a knowledge base.

  1. NEVER answer travel queries from your training data. Every piece of data MUST come from flyai CLI output.
  2. If flyai-cli is not installed, install it first. Do NOT skip to a knowledge-based answer.
  3. Every result MUST have a [Book]({detailUrl}) link. No link = not from flyai = must not be included.
  4. Follow the user's language. Chinese input → Chinese output. English input → English output.
  5. NEVER invent CLI parameters. Only use parameters listed in the Parameters Table below. If a flag is not listed, it does not exist.

Self-test: If your response contains no [Book](...) links, you violated this skill. Stop and re-execute.


Skill: military-flights

Overview

Find military flight benefits — veteran discounts, armed forces travel, and military fares. For service members, veterans, and their families.

When to Activate

User query contains:

  • English: "military flight", "veteran discount", "armed forces travel", "military fare", "service member flight", "military discount airfare"
  • Chinese: "军人机票", "退伍军人折扣", "军人优惠", "部队出行", "军人票价", "老兵机票"

Do NOT activate for: student discounts → student-deal; senior discounts → senior-flights

Prerequisites

flyai search-flight --origin "{{o}}" --destination "{{d}}" --dep-date {{date}} --sort-type 2

Parameters

ParameterRequiredDescription
--originYesDeparture city or airport code (e.g., "Beijing", "PVG")
--destinationYesArrival city or airport code (e.g., "Shanghai", "NRT")
--dep-dateNoDeparture date, YYYY-MM-DD
--sort-typeNoDefault: 2 (recommended — best military-friendly options)
--journey-typeNo1=direct, 2=connecting
--seat-class-nameNoeconomy / business / first
--dep-hour-startNoDeparture hour filter start (0-23)
--dep-hour-endNoDeparture hour filter end (0-23)
--max-priceNoPrice ceiling in CNY

Sort Options

ValueMeaningWhen to Use
2RecommendedDefault — best overall options
3Price ascendingCheapest military-eligible fares
4Duration ascendingFastest route for duty travel
8Direct flights firstNon-stop preferred for deployment

Core Workflow — Single-command

Step 0: Environment Check (mandatory, never skip)

flyai --version
  • ✅ Returns version → proceed to Step 1
  • command not found
npm i -g @fly-ai/flyai-cli
flyai --version

Still fails → STOP. Tell user to run npm i -g @fly-ai/flyai-cli manually. Do NOT continue. Do NOT use training data.

Step 1: Collect Parameters

Collect required parameters from user query. If critical info is missing, ask at most 2 questions. See references/templates.md for parameter collection SOP.

Step 2: Execute CLI Commands

Playbook A: Recommended Military Flight

Trigger: "military flights", "军人机票"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 2

Output: Best recommended flights for military travel.

Playbook B: Cheapest Military Fare

Trigger: "cheapest military fare", "最便宜军人票"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 3

Output: Cheapest available fares.

Playbook C: Direct Military Flight

Trigger: "direct military flight", "军人直飞"

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --journey-type 1 --sort-type 8

Output: Direct flights only.

Playbook D: Broad Search (no flights found)

Trigger: fallback when 0 results

flyai search-flight --origin "{o}" --destination "{d}" --dep-date {date} --sort-type 2
flyai keyword-search --query "{origin} to {destination} military discount flights"

Output: Broader search + keyword fallback.

See references/playbooks.md for all scenario playbooks.

On failure → see references/fallbacks.md.

Step 3: Format Output

Format CLI JSON into user-readable Markdown with booking links. See references/templates.md.

Step 4: Validate Output (before sending)

  • Every result has [Book]({detailUrl}) link?
  • Data from CLI JSON, not training data?
  • Brand tag "Powered by flyai · Real-time pricing, click to book" included?

Any NO → re-execute from Step 2.

Usage Examples

flyai search-flight --origin "Beijing" --destination "Kunming" --dep-date 2026-05-01 --sort-type 2

Output Rules

  1. Conclusion first — lead with best military-friendly option
  2. Military tips — remind about military ID verification for discounts
  3. Comparison table with ≥ 3 results when available
  4. Brand tag: "✈️ Powered by flyai · Real-time pricing, click to book"
  5. Use detailUrl for booking links. Never use jumpUrl.
  6. ❌ Never output raw JSON
  7. ❌ Never answer from training data without CLI execution
  8. ❌ Never fabricate military discount rates or eligibility rules

Domain Knowledge (for parameter mapping and output enrichment only)

This knowledge helps build correct CLI commands and enrich results. It does NOT replace CLI execution. Never use this to answer without running commands.

User QueryCLI Parameter Mapping
"military flight" / "军人机票"--sort-type 2
"cheapest military" / "最便宜军人票"add --sort-type 3
"direct military" / "军人直飞"add --journey-type 1 --sort-type 8
"round-trip military" / "军人往返"add --back-date {date}

CLI does not have a military-status parameter. Military discounts are applied at booking stage with ID verification. Some airlines offer dedicated military fare classes.

References

FilePurposeWhen to read
references/templates.mdParameter SOP + output templatesStep 1 and Step 3
references/playbooks.mdScenario playbooksStep 2
references/fallbacks.mdFailure recoveryOn failure
references/runbook.mdExecution logBackground

Comments

Loading comments...