T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Commercial Output and Session-Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a hot-springs search helper, but it asks agents to install an unpinned global CLI, force commercial booking-link output, and persist raw user queries locally without enough disclosure or control.
Review before installing. Only use this skill if you are comfortable with FlyAI being the required data source, booking links appearing in results, a global npm CLI being installed, and local logs potentially storing raw travel queries. Prefer a pinned, user-approved, isolated CLI install and disable or redact persistent logging.
SKILL.md:10Commercial Output and Session-Behavior Hijacking
SKILL.md:32Mandatory Unpinned Global Installation of a Third-Party npm Package
references/runbook.md:33Plaintext Logging of Raw User Queries and Unsafe Shell-Based Log Construction
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-poi --city-name "Huangshan" --category "温泉"
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The manifest description says this skill supports flights, hotels, train tickets, attraction tickets, itinerary planning, visa info, travel insurance, car rental, and more. However, the documented workflow and commands in this file are limited to flyai search-poi for hot-spring attractions, with no corresponding implementation for those additional travel services.
The skill instructs the agent to install a global npm package and frames that step as mandatory, but does not warn that this modifies the host environment or may execute untrusted package lifecycle scripts. In an agent setting, this can lead to unintended system changes, supply-chain exposure, and elevated risk if the package or dependency chain is compromised.
The prerequisites section directs a global npm i -g install without any safety disclosure, encouraging persistent system modification as part of normal skill use. Because npm installation can run package scripts and alter PATH-visible tooling, this creates a meaningful supply-chain and host-integrity risk in environments where the agent may execute commands automatically.
The fallback logic repeats the global installation command as an automatic recovery step, which increases the chance that an agent will modify the system without meaningful review when a command is missing. This is dangerous because failure-handling paths are often triggered automatically, turning a missing dependency into an implicit authorization to install third-party code.
This markdown file defines a trigger using a short natural-language phrase that could plausibly appear in ordinary conversation or general travel queries. The playbook does not provide negative examples, context limits, or other constraints to clarify when this skill should activate versus when it should not.
The runbook explicitly instructs the agent to log the raw user query (user_query) and to persist execution logs to a local file when possible, but it provides no notice, minimization, redaction, retention, or access-control guidance. In a travel skill, raw queries may contain sensitive personal and trip data such as names, locations, dates, booking details, or even passport/visa-related information, so storing them verbatim increases privacy and data-exposure risk.
Line L135 states both 'Use detailUrl for booking links' and 'Never use detailUrl.' These instructions cannot both be true, creating an active documentation contradiction about how links should be produced.
No suspicious patterns detected.