T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Mandatory Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This flight-search skill is not clearly malicious, but it asks agents to install and run an unpinned global CLI and persist raw travel queries without adequate disclosure.
Review this skill before installing. It is intended to search live connecting-flight options through flyai/Fliggy, but you should require manual approval for any npm installation, prefer a pinned or isolated CLI install, avoid executing generated command strings through a shell, and disable or sanitize the local execution log before using it with personal travel details.
SKILL.md:10Mandatory Commercial Output and Agent Behavior Hijacking
SKILL.md:72Unpinned Global Installation of a Third-Party CLI Package
SKILL.md:101Shell Command Injection Through User-Controlled Travel Parameters
references/runbook.md:5Unsafe Persistent Logging of Raw User Queries and Commands
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-flight --origin "Shanghai" --destination "Lhasa" --dep-date 2026-06-01 --journey-type 2 --sort-type 4
## Output Rules
1. **Conclusion first** — lead with cheapest or fastest connecting option
2. **Layover info** — show transit city and connection time when available
The skill frames the agent as a CLI executor and mandates installing and running a global package if the tool is missing, but gives no user-facing consent or warning about modifying the host system. In agent environments, this can lead to unapproved package installation and code execution from an external registry.
These lines directly instruct npm i -g @fly-ai/flyai-cli followed by execution, which is a supply-chain and host-modification risk when performed automatically by an agent. Without an explicit warning and consent boundary, the skill encourages arbitrary software installation and immediate execution on the user's machine or runner.
The skill explicitly says agents must never invent CLI parameters, yet later instructs adding --transfer-city, which is absent from the declared parameter table. This contradiction can cause agents to execute unsupported commands, fail unpredictably, or normalize unsafe parameter guessing when interacting with external CLIs.
The playbook defines activation phrases in both English and Chinese, including Chinese-only trigger options such as "中转航班" and "最快中转", but it does not explain whether the skill is intended for bilingual use or offer user language selection. This creates a natural-language policy concern because locale behavior is embedded without opt-in or documented regional justification.
This is a real integrity/behavioral flaw: the playbook promises a route constrained to a specified transit city, but the command omits any transfer-city argument and performs only a generic connecting-flight search. In a travel-booking context, this can mislead users into selecting itineraries that do not meet visa, airport, layover, or personal routing requirements, causing booking errors and downstream financial or travel disruption.
The runbook explicitly records user_query as raw input in an internal execution log, which can capture personal data, travel plans, names, contact details, passport or visa-related information, and other sensitive user content. Because the log is maintained internally and 'not shown to users' with no notice, minimization, redaction, or retention controls, this creates a privacy and data-handling vulnerability rather than a purely operational detail.
The runbook instructs the agent to append execution logs to a local file, which increases the chance that sensitive operational data and raw queries remain on disk beyond the active session. In a travel-booking context, those logs may contain itinerary details and other sensitive metadata, and the lack of disclosure, storage safeguards, or lifecycle management makes the local persistence risky.
The instruction says to follow the user's language and specifically requires output in Chinese if the user writes Chinese. This is a language-handling policy embedded in natural language, and it does not offer an explicit user choice or opt-in beyond inferred input language.
No suspicious patterns detected.