amex-travel

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core behavior matches its stated purpose, but it relies on anti-detection browser automation, persistent session profiles, direct handling of Amex credentials, and optional arbitrary command execution for 2FA. Data appears to flow to the official service rather than a clear theft endpoint, so this is not confirmed malware, but it carries meaningful security and trust risk.

Confidence: 79%Severity: 64%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:15 AM
Package URL
pkg:socket/skills-sh/borski%2Ftravel-hacking-toolkit%2Famex-travel%2F@8f89c30a559765b66109b847b705a116dd876b21
Security Audit — socket — amex-travel