T01 · Skill Instruction Hijacking
- Location
SKILL.md:11- Finding
Forced Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This packing-list skill is review-worthy because it forces a third-party travel CLI, booking links, global package installation, and local raw-query logging for a task that should need much narrower authority.
Review carefully before installing. This skill may install and run a global third-party CLI, send travel queries to that service, add booking links and branding to answers, and keep raw prompts in a local log. It should be narrowed, require explicit install approval, avoid shell interpolation, and disclose or minimize logging before general use.
SKILL.md:11Forced Commercial Output and Agent Behavior Hijacking
SKILL.md:40Automatic Installation of an Unpinned Global npm Dependency
SKILL.md:72Shell Command Injection Through User-Controlled Query Interpolation
references/runbook.md:7Unsafe Plaintext Logging and Shell Injection in Execution-Log Persistence
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai keyword-search --query "旅行清单 日本"
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The skill is presented as a packing-list helper, but the manifest and instructions expand it into broad travel search and booking workflows. This scope expansion can cause the agent to invoke the skill for unrelated travel requests and perform actions or present booking-oriented results outside the user's expected intent, increasing the risk of deceptive behavior and unsafe tool use.
The description advertises broad travel capabilities far beyond packing lists, creating ambiguity about when this skill should activate. In an agentic environment, such ambiguity can hijack routing for many travel-related queries and expose users to unnecessary third-party workflow execution or commercially biased outputs.
The core instructions require every result to contain a booking link and prohibit answering without CLI-derived links, which conflicts with the stated packing-list purpose. This creates a strong incentive for the agent to transform a benign informational task into a commercial search/booking workflow, potentially misleading users and causing unnecessary external calls or affiliate-style redirection.
The manifest describes a broad travel assistant with many transactional travel capabilities, but this file only defines command sequences for packing-list searches. That is a semantic mismatch between the claimed scope and the implemented behavior shown here, because the documented operations are much narrower than the manifest promises.
The trigger phrase "what to pack" is broad enough to match ordinary conversation, which can cause unintended invocation of the playbook. In an agent setting, over-broad triggers can redirect user requests into tool-backed flows without clear intent, producing irrelevant queries or surprising behavior that weakens user control.
The playbooks hard-code Chinese-language search queries regardless of the user's language or locale, which can silently alter the meaning, relevance, or source population of returned results. In a travel assistant context, this is risky because users may receive inaccurate or poorly understood packing guidance, and the hidden locale shift reduces transparency and informed consent.
The statement that the execution log is 'Not shown to users' creates an instruction to conceal operational logging from users, reducing transparency around collection of potentially sensitive request data. While internal logs are common, explicitly hiding them without disclosure is risky here because the same runbook also records raw user input and writes logs to disk, making the concealment materially relevant rather than harmless.
The runbook explicitly logs raw user input in user_query and instructs persisting execution logs to disk, which can capture sensitive travel details, personal identifiers, and possibly booking-related data without any retention limits, minimization, or user disclosure. In a travel skill context, this is more dangerous because user prompts may include names, destinations, dates, passport/visa questions, and other sensitive itinerary information that could be exposed through local files or downstream log handling.
No suspicious patterns detected.