Back to skill

Security audit

Plan Dubai Travel — Flights, Hotels, Burj Khalifa, Desert Safari, Malls & Itineraries

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent travel-booking helper, but it requires an unpinned global CLI install and can persist raw user travel queries without clear consent.

Review this skill before installing. It may install a third-party npm CLI globally, route travel searches through that CLI, show booking links and flyai branding, and write raw travel-query details to a local log. Use it only if you are comfortable with those behaviors, preferably after manually installing a reviewed CLI version in an isolated environment and disabling or removing raw-query logging.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:8
Finding

Mandatory Commercial Output and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:34
Finding

Automatic Installation and Execution of an Unpinned Global npm Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/runbook.md:1
Finding

Hidden Raw-Query Persistence and Shell Injection Risk in Execution Logging

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The runbook instructs the agent to retain `{raw input}`, collected parameters, full CLI commands, fallback commands, and execution metadata in a hidden file that is explicitly “not shown to users.” Travel requests can contain personal information such as origin, destination, dates, accommodation preferences, and free-form text. No consent, redaction, access-control, retention, or deletion policy is defined. The proposed p ...[truncated 2419 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

flyai search-flight --origin "Beijing" --destination "Dubai" --dep-date 2026-01-15 --sort-type 3

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to install a global npm package if the CLI is missing, which modifies the host environment without prior user approval or a safety warning. In an agent setting, this can lead to unexpected system changes, supply-chain exposure, and violation of least-privilege expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prerequisites section presents a global npm i -g command as a normal setup step without disclosing that it alters the system and installs third-party code. This is risky in autonomous or semi-autonomous agent contexts because users may not realize the skill can trigger persistent environment changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow mandates automatic installation on command failure and tells the agent not to continue without it, creating pressure to execute a system-modifying command autonomously. That increases the chance of unreviewed package installation and associated supply-chain or persistence risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The runbook explicitly stores the raw user query in an internal execution log and may persist that log to disk, yet the file states it is 'Not shown to users' and provides no notice, minimization, or retention controls. In a travel-booking context, user queries can contain personal and sensitive data such as names, travel dates, destinations, booking preferences, passport/visa details, or other identifiers, so retaining raw input increases privacy and compliance risk if logs are accessed, leaked, or over-retained.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest identifies the skill as "dubai-travel", but this documentation header says "Templates — explore-dubai". This is an active documentation-level inconsistency about the skill's identity and intended packaging, which can mislead maintainers about what skill these templates belong to.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.