T01 · Skill Instruction Hijacking
- Location
SKILL.md:8- Finding
Mandatory Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent travel-booking helper, but it requires an unpinned global CLI install and can persist raw user travel queries without clear consent.
Review this skill before installing. It may install a third-party npm CLI globally, route travel searches through that CLI, show booking links and flyai branding, and write raw travel-query details to a local log. Use it only if you are comfortable with those behaviors, preferably after manually installing a reviewed CLI version in an isolated environment and disabling or removing raw-query logging.
SKILL.md:8Mandatory Commercial Output and Agent Behavior Hijacking
SKILL.md:34Automatic Installation and Execution of an Unpinned Global npm Dependency
references/runbook.md:1Hidden Raw-Query Persistence and Shell Injection Risk in Execution Logging
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-flight --origin "Beijing" --destination "Dubai" --dep-date 2026-01-15 --sort-type 3
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The skill explicitly instructs the agent to install a global npm package if the CLI is missing, which modifies the host environment without prior user approval or a safety warning. In an agent setting, this can lead to unexpected system changes, supply-chain exposure, and violation of least-privilege expectations.
The prerequisites section presents a global npm i -g command as a normal setup step without disclosing that it alters the system and installs third-party code. This is risky in autonomous or semi-autonomous agent contexts because users may not realize the skill can trigger persistent environment changes.
The workflow mandates automatic installation on command failure and tells the agent not to continue without it, creating pressure to execute a system-modifying command autonomously. That increases the chance of unreviewed package installation and associated supply-chain or persistence risks.
The runbook explicitly stores the raw user query in an internal execution log and may persist that log to disk, yet the file states it is 'Not shown to users' and provides no notice, minimization, or retention controls. In a travel-booking context, user queries can contain personal and sensitive data such as names, travel dates, destinations, booking preferences, passport/visa details, or other identifiers, so retaining raw input increases privacy and compliance risk if logs are accessed, leaked, or over-retained.
The manifest identifies the skill as "dubai-travel", but this documentation header says "Templates — explore-dubai". This is an active documentation-level inconsistency about the skill's identity and intended packaging, which can mislead maintainers about what skill these templates belong to.
No suspicious patterns detected.