Night Market Guide

Security checks across malware telemetry and agentic risk

Overview

This night-market guide is travel-related, but it tells the agent to globally install and run a third-party booking CLI automatically, so users should review it before use.

Install only if you are comfortable with an agent using FlyAI/Fliggy for results and installing a global npm CLI. Approve the CLI installation yourself, consider checking the npm package first, and treat booking links as commercial provider links rather than neutral rankings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description advertises a very broad set of unrelated travel capabilities ('flight booking, hotel reservation, train tickets... and more') despite the skill being named and framed as a night-market finder. This can cause unintended invocation overlap, routing users into this skill for tasks outside its scoped purpose, increasing the chance the agent executes unnecessary commands or follows this file's mandatory install/CLI workflow in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal