Back to skill

Security audit

connecting

Security checks for vulnerabilities and agentic risk

Overview

This flight-search skill is not clearly malicious, but it asks agents to install and run an unpinned global CLI and persist raw travel queries without adequate disclosure.

Review this skill before installing. It is intended to search live connecting-flight options through flyai/Fliggy, but you should require manual approval for any npm installation, prefer a pinned or isolated CLI install, avoid executing generated command strings through a shell, and disable or sanitize the local execution log before using it with personal travel details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:10
Finding

Mandatory Commercial Output and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:72
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:101
Finding

Shell Command Injection Through User-Controlled Travel Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/runbook.md:5
Finding

Unsafe Persistent Logging of Raw User Queries and Commands

Content
View full analysis
> .flyai-execution-log.json ``` ### Technical Analysis The runbook instructs the agent to retain the raw user query, collected parameters, complete CLI commands, and recovery commands in `.flyai-execution-log.json`. It defines no consent requirement, data-minimization policy, redaction, retention limit, access-control requirement, or secure deletion procedure. Travel requests can contain personal itinerary details. Users may also accidentally include identifiers, credentials, or other sensitive content. Persisting the raw query and generated commands leaves this information available beyond the immediate interaction. The log is appended through a shell command using a single-quoted generated JSON value. A raw query containing a single quote can terminate the quoted string. If attacker-controlled content is serialized into `generation_log_json` without safe shell handling, it ca ...[truncated 1417 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

flyai search-flight --origin "Shanghai" --destination "Lhasa" --dep-date 2026-06-01 --journey-type 2 --sort-type 4

text

## Output Rules

1. **Conclusion first** — lead with cheapest or fastest connecting option
2. **Layover info** — show transit city and connection time when available

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill frames the agent as a CLI executor and mandates installing and running a global package if the tool is missing, but gives no user-facing consent or warning about modifying the host system. In agent environments, this can lead to unapproved package installation and code execution from an external registry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

These lines directly instruct npm i -g @fly-ai/flyai-cli followed by execution, which is a supply-chain and host-modification risk when performed automatically by an agent. Without an explicit warning and consent boundary, the skill encourages arbitrary software installation and immediate execution on the user's machine or runner.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly says agents must never invent CLI parameters, yet later instructs adding --transfer-city, which is absent from the declared parameter table. This contradiction can cause agents to execute unsupported commands, fail unpredictably, or normalize unsafe parameter guessing when interacting with external CLIs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The playbook defines activation phrases in both English and Chinese, including Chinese-only trigger options such as "中转航班" and "最快中转", but it does not explain whether the skill is intended for bilingual use or offer user language selection. This creates a natural-language policy concern because locale behavior is embedded without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This is a real integrity/behavioral flaw: the playbook promises a route constrained to a specified transit city, but the command omits any transfer-city argument and performs only a generic connecting-flight search. In a travel-booking context, this can mislead users into selecting itineraries that do not meet visa, airport, layover, or personal routing requirements, causing booking errors and downstream financial or travel disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The runbook explicitly records user_query as raw input in an internal execution log, which can capture personal data, travel plans, names, contact details, passport or visa-related information, and other sensitive user content. Because the log is maintained internally and 'not shown to users' with no notice, minimization, redaction, or retention controls, this creates a privacy and data-handling vulnerability rather than a purely operational detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The runbook instructs the agent to append execution logs to a local file, which increases the chance that sensitive operational data and raw queries remain on disk beyond the active session. In a travel-booking context, those logs may contain itinerary details and other sensitive metadata, and the lack of disclosure, storage safeguards, or lifecycle management makes the local persistence risky.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says to follow the user's language and specifically requires output in Chinese if the user writes Chinese. This is a language-handling policy embedded in natural language, and it does not offer an explicit user choice or opt-in beyond inferred input language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.