T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Forced Commercial Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This trip-planning skill has a coherent purpose, but it asks agents to install and run an unpinned global CLI, force commercial booking-link output, and persist raw travel queries in a hidden local log.
Review before installing. Only use this skill if you are comfortable with a third-party travel CLI being installed globally and used as the sole travel-data source, with booking links and flyai branding in responses. Avoid entering sensitive personal, passport, visa, or confidential itinerary details unless the logging behavior is removed or clearly controlled.
SKILL.md:9Forced Commercial Output and Agent Behavior Hijacking
SKILL.md:31Unpinned Global Installation and Execution of a Third-Party npm Package
SKILL.md:137Shell Command Injection Through User-Controlled CLI Placeholders
references/runbook.md:5Unsafe Persistent Logging of Raw User Queries and Commands
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai search-flight --origin "Shanghai" --destination "Tokyo" --dep-date 2026-05-01 --sort-type 3
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The skill directs the agent to install and run a global npm package on the local system without an explicit user-consent gate or warning. That creates a supply-chain and local-execution risk: a broadly triggered skill could cause an agent to fetch and execute untrusted code or alter the user's environment unexpectedly.
The activation section uses broad phrases like "itinerary," "travel planning," and "organize my vacation," which can appear in ordinary conversation and overlap with many adjacent travel tasks. The exclusion guidance is also vague because it says "specific type → see specialized planners" without defining clear boundaries or negative examples in this file.
The runbook explicitly logs user_query as raw input, which can capture sensitive travel data such as names, dates, locations, booking details, passport/visa information, and other personal content. Because the document says this log is maintained internally and not shown to users, the skill creates undisclosed data collection and retention risk with no minimization, redaction, or consent mechanism.
Taken together, the schema stores raw natural-language user input and instructs the agent to persist execution records locally, creating a straightforward data retention and leakage path. In a trip-planning skill, user prompts are especially likely to contain sensitive PII and travel-intent data, so the context makes the issue more dangerous than a generic low-sensitivity skill.
The persistence instructions append execution logs to .flyai-execution-log.json, which turns transient operational data into retained local data without any user-facing warning. If those logs contain queries, commands, booking links, or risk notes, they can be exposed to other local processes, operators, backups, or later compromise of the host environment.
Line L223 states 'earliest = cheapest', but elsewhere the file defines --sort-type 3 as price ascending and --sort-type 6 as earliest departure. This is an active contradiction in the skill's own documentation that could cause the agent to choose the wrong flight-selection behavior.
No suspicious patterns detected.