Back to skill

Security audit

Hot Springs

Security checks for vulnerabilities and agentic risk

Overview

The skill is a hot-springs search helper, but it asks agents to install an unpinned global CLI, force commercial booking-link output, and persist raw user queries locally without enough disclosure or control.

Review before installing. Only use this skill if you are comfortable with FlyAI being the required data source, booking links appearing in results, a global npm CLI being installed, and local logs potentially storing raw travel queries. Prefer a pinned, user-approved, isolated CLI install and disable or redact persistent logging.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:10
Finding

Commercial Output and Session-Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:32
Finding

Mandatory Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/runbook.md:33
Finding

Plaintext Logging of Raw User Queries and Unsafe Shell-Based Log Construction

Content
View full analysis
> .flyai-execution-log.json ``` ``` ### Technical Analysis The runbook instructs the agent to store the complete raw user query, timestamps, command details, fallback behavior, and output metadata in `.flyai-execution-log.json`. It states that the log is internal and not shown to users, but it does not require user consent, minimization, redaction, encryption, restrictive permissions, rotation, retention limits, or deletion. Travel queries can contain personal data such as intended destinations, dates, companions, accessibility needs, health-related preferences, or location information. Retaining the raw input in a hidden plaintext file creates an avoidable confidentiality risk. The proposed persistence command also interpol ...[truncated 2341 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

flyai search-poi --city-name "Huangshan" --category "温泉"

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says this skill supports flights, hotels, train tickets, attraction tickets, itinerary planning, visa info, travel insurance, car rental, and more. However, the documented workflow and commands in this file are limited to flyai search-poi for hot-spring attractions, with no corresponding implementation for those additional travel services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to install a global npm package and frames that step as mandatory, but does not warn that this modifies the host environment or may execute untrusted package lifecycle scripts. In an agent setting, this can lead to unintended system changes, supply-chain exposure, and elevated risk if the package or dependency chain is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prerequisites section directs a global npm i -g install without any safety disclosure, encouraging persistent system modification as part of normal skill use. Because npm installation can run package scripts and alter PATH-visible tooling, this creates a meaningful supply-chain and host-integrity risk in environments where the agent may execute commands automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The fallback logic repeats the global installation command as an automatic recovery step, which increases the chance that an agent will modify the system without meaningful review when a command is missing. This is dangerous because failure-handling paths are often triggered automatically, turning a missing dependency into an implicit authorization to install third-party code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file defines a trigger using a short natural-language phrase that could plausibly appear in ordinary conversation or general travel queries. The playbook does not provide negative examples, context limits, or other constraints to clarify when this skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The runbook explicitly instructs the agent to log the raw user query (user_query) and to persist execution logs to a local file when possible, but it provides no notice, minimization, redaction, retention, or access-control guidance. In a travel skill, raw queries may contain sensitive personal and trip data such as names, locations, dates, booking details, or even passport/visa-related information, so storing them verbatim increases privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L135 states both 'Use detailUrl for booking links' and 'Never use detailUrl.' These instructions cannot both be true, creating an active documentation contradiction about how links should be produced.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.