T01 · Skill Instruction Hijacking
- Location
SKILL.md:8- Finding
Mandatory FlyAI Output and Agent Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This WiFi rental skill supports a coherent travel-search workflow, but it should be reviewed because it can auto-install a global CLI and persist raw user queries in a hidden local log.
Before installing, confirm you are comfortable with a FlyAI/Fliggy-centered booking workflow, global installation of `@fly-ai/flyai-cli`, and local logging of travel queries. Prefer requiring explicit approval before installation, pinning and verifying the CLI package, disabling raw-query logging, and removing mandatory promotional branding or provider-exclusive result filtering.
SKILL.md:8Mandatory FlyAI Output and Agent Behavior Hijacking
SKILL.md:37Unpinned Global npm Package Installation
references/runbook.md:31Shell Injection and Undisclosed Plaintext Query Logging
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
flyai keyword-search --query "日本WiFi租赁"
## Output Rules
1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available
The manifest presents this as a narrow pocket-WiFi skill, but the description and instructions expand scope into broad travel booking and itinerary functions. This scope mismatch can cause an agent or user to invoke the skill in contexts they did not intend, increasing the chance of overbroad actions, unexpected data handling, or execution of unrelated travel workflows.
The skill instructs the agent to install a global npm package automatically if the CLI is missing, which modifies the host environment without explicit user approval. This creates supply-chain and system-integrity risk, especially because installation happens as a prerequisite to answering a query rather than as an opt-in action.
The runbook explicitly records user_query as raw input and appends the full execution log to a local file, creating unnecessary retention of potentially sensitive personal data. In a travel-booking context, user queries may contain names, dates, destinations, passport or visa details, contact information, and other travel-sensitive data, so persistent plaintext logging increases privacy, compliance, and data exposure risk.
This markdown file includes npm i -g @fly-ai/flyai-cli, which performs a global package installation and changes the user's environment. The surrounding instructions do not warn the user that this command installs software system-wide or may require elevated privileges.
No suspicious patterns detected.