Back to skill

Security audit

Test

Security checks for vulnerabilities and agentic risk

Overview

This skill is for private-car travel search, but it requires an unpinned global CLI install and forces provider booking links and branding in the answer.

Review this carefully before installing. Only use it if you are comfortable installing and running the FlyAI CLI globally, receiving results limited to that provider, and seeing mandatory booking links and branding. Prefer a pinned, local, user-approved install or a version that can fail safely without installing software automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:8
Finding

Mandatory Commercial Output and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:36
Finding

Mandatory Installation of an Unpinned Global npm Dependency

Content
View full analysis
Remediation
View remediation
`. 4. Verify package integrity using a lockfile, cryptographic digest, signed provenance, or an equivalent trusted verification mechanism. 5. Review the package and its complete transitive dependency tree before approving it for execution. 6. Prefer a project-local, sandboxed installation over `npm i -g`. 7. Execute the CLI in a restricted container or sandbox with minimal filesystem, credential, and network access. 8. Disable npm lifecycle scripts with `--ignore-scripts` where compatible, or separately audit every required lifecycle script. 9. Avoid administrative execution and document that users must not work around installation failures with `sudo`. 10. Provide a safe failure mode when the dependency is unavailable instead of forcing installation or refusing all assistance. ]]>
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

flyai keyword-search --query "包车一日游 杭州"

text

## Output Rules

1. **Conclusion first** — lead with the key finding
2. **Comparison table** with ≥ 3 results when available

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description claims support for many travel services beyond private-car tours, yet the workflow and examples in this file only show flyai keyword-search queries for private-car day tours, half-day trips, and multi-day driver services. This creates a clear description-behavior mismatch because the actual documented operations are materially narrower than the advertised scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill also supports flights, hotels, train tickets, attraction tickets, visa info, insurance, car rental, and more, but the in-file activation rules explicitly trigger only for private-car intents and even redirect car rental elsewhere. This is an active contradiction between the skill's own descriptive documentation and its operational instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.