flightai
What this skill does
flightAI is a travel-related skill focused on flight ticket assistance, including flight searches, seat queries, order creation, endorsements, and cancellations. It interacts with an external API for
github/leoyeai - Data Exfiltration - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=flightaiAssessments (3)
Data Exfiltration
Data Exfiltration via local-llm-review
scripts/auth.py
The script sends user phone numbers to an external API for verification and stores the resulting API key in a temporary file. This could be a risk if the API endpoint is not secure or if the API key iData Exfiltration via local-llm-review
scripts/create_order.py
The script processes user personal information (passenger name, phone, ID) and sends it to an external API for order creation. This could be a risk if the API endpoint is not secure or if the data is Insecure Storage
Insecure Storage via local-llm-review
scripts/common.py
The script stores the API key in a temporary file on the local filesystem. This could be a risk if the temporary directory is not properly secured or if the file is accessible to other processes.Badge
Add the Anomity scan badge for flightai to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of flightai? Report an issue or request a rescan.




