Back to skill

Security audit

Plan Your Trip — Itinerary Builder, Flight + Hotel Bundles, Day-by-Day Travel Planning

Security checks for vulnerabilities and agentic risk

Overview

This trip-planning skill has a coherent purpose, but it asks agents to install and run an unpinned global CLI, force commercial booking-link output, and persist raw travel queries in a hidden local log.

Review before installing. Only use this skill if you are comfortable with a third-party travel CLI being installed globally and used as the sole travel-data source, with booking links and flyai branding in responses. Avoid entering sensitive personal, passport, visa, or confidential itinerary details unless the logging behavior is removed or clearly controlled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:9
Finding

Forced Commercial Output and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:31
Finding

Unpinned Global Installation and Execution of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:137
Finding

Shell Command Injection Through User-Controlled CLI Placeholders

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/runbook.md:5
Finding

Unsafe Persistent Logging of Raw User Queries and Commands

Content
View full analysis
> .flyai-execution-log.json ``` ### Technical Analysis The runbook directs the agent to retain the complete raw user query and every generated command. Travel requests can expose sensitive itinerary details, including locations, dates, preferences, budget, and potentially identity-related information. The data is appended to a hidden plaintext file without specified user consent, file permissions, retention limits, encryption, redaction, or deletion procedures. The relative path may place the log inside a project or repository, creating a risk of accidental backup or source-control inclusion. The proposed `echo` command also embeds generated JSON into ...[truncated 1567 chars]
Remediation
View remediation
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

flyai search-flight --origin "Shanghai" --destination "Tokyo" --dep-date 2026-05-01 --sort-type 3

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to install and run a global npm package on the local system without an explicit user-consent gate or warning. That creates a supply-chain and local-execution risk: a broadly triggered skill could cause an agent to fetch and execute untrusted code or alter the user's environment unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation section uses broad phrases like "itinerary," "travel planning," and "organize my vacation," which can appear in ordinary conversation and overlap with many adjacent travel tasks. The exclusion guidance is also vague because it says "specific type → see specialized planners" without defining clear boundaries or negative examples in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The runbook explicitly logs user_query as raw input, which can capture sensitive travel data such as names, dates, locations, booking details, passport/visa information, and other personal content. Because the document says this log is maintained internally and not shown to users, the skill creates undisclosed data collection and retention risk with no minimization, redaction, or consent mechanism.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Taken together, the schema stores raw natural-language user input and instructs the agent to persist execution records locally, creating a straightforward data retention and leakage path. In a trip-planning skill, user prompts are especially likely to contain sensitive PII and travel-intent data, so the context makes the issue more dangerous than a generic low-sensitivity skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The persistence instructions append execution logs to .flyai-execution-log.json, which turns transient operational data into retained local data without any user-facing warning. If those logs contain queries, commands, booking links, or risk notes, they can be exposed to other local processes, operators, backups, or later compromise of the host environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L223 states 'earliest = cheapest', but elsewhere the file defines --sort-type 3 as price ascending and --sort-type 6 as earliest departure. This is an active contradiction in the skill's own documentation that could cause the agent to choose the wrong flight-selection behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.