Back to skill

Security audit

Plan Bali Travel — Flights, Hotels, Attractions, Temples, Beaches, Villas & Itineraries

Security checks across malware telemetry and agentic risk

Overview

This Bali travel skill is purpose-aligned, but it should be reviewed because it can install a global CLI and persist raw travel requests in a hidden local log.

Install only if you are comfortable with the agent running FlyAI/Fliggy CLI commands and installing a global npm package. Avoid entering passport, payment, or highly personal travel details, and ask the agent not to create or retain `.flyai-execution-log.json` unless you explicitly want local logging.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "Bali trip" is broad enough to match many ordinary user requests about Bali travel, which can cause this playbook to activate when the user did not intend a specific canned workflow. In a booking-capable travel skill, accidental invocation can steer users into preselected actions or parameter mappings, increasing the risk of incorrect bookings or unwanted transactional flows.

Vague Triggers

Low
Confidence
84% confidence
Finding
The phrase "luxury Bali" is underspecified and may be invoked from normal conversation about upscale Bali travel rather than an intentional request to run a predefined automation. Because this skill supports reservations and itinerary generation, ambiguous activation could result in the system applying premium defaults or expensive options without clear user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger "Bali adventure" is ambiguous and can easily overlap with common trip-planning language, making unintended activation plausible during routine discussion. In this context, the playbook bundles flights, lodging, and activities, so a false trigger could bias recommendations or initiate downstream booking steps that do not reflect the user's real preferences or budget.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The runbook explicitly logs raw user input, CLI commands, status, and latency in an internal execution log without any notice, minimization, or retention controls. In a travel-booking skill, user queries can contain names, contact details, passport or visa details, booking references, and itinerary information, so persistent capture of this data creates a meaningful privacy and sensitive-data exposure risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The runbook instructs appending execution logs to a local file, which creates persistent storage of potentially sensitive operational and user-derived data. If the host is shared, compromised, or improperly permissioned, the log file can expose travel queries, booking activity, and command history beyond the original transaction.

Ssd 3

Medium
Confidence
97% confidence
Finding
The schema requires storing raw input in an internal execution log, which is a direct collection of unfiltered user content and may include sensitive personal or travel-related data. Because this skill supports flights, hotels, visas, insurance, and car rentals, the context increases risk: users are more likely to submit identifying, financial, or document-related information that should not be broadly retained in logs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.