american-airlines

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities mostly align: it logs into AA to read loyalty data and explicitly requires the user to supply the email 2FA code. Main risk comes from unpinned automation dependencies, anti-detection tooling, sensitive session persistence, and especially the optional mutable personal Docker image that would receive AA credentials. Overall this is better classified as suspicious/high-risk tooling rather than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:14 AM
Package URL
pkg:socket/skills-sh/borski%2Ftravel-hacking-toolkit%2Famerican-airlines%2F@c1319ff438efa2c25d1740f67ccb414eb1bef13a
Security Audit — socket — american-airlines