chase-travel
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill's stated purpose and core capability are broadly aligned: it automates Chase portal searches without booking. The main risk is trust, not hidden purpose: it asks for highly sensitive bank credentials and MFA input, then routes them through third-party anti-detection browser automation and optionally an unpinned third-party Docker image. That makes the skill suspicious and high-risk to use, though not confirmed malware.
Confidence: 87%Severity: 82%
Audit Metadata