chase-travel

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose and core capability are broadly aligned: it automates Chase portal searches without booking. The main risk is trust, not hidden purpose: it asks for highly sensitive bank credentials and MFA input, then routes them through third-party anti-detection browser automation and optionally an unpinned third-party Docker image. That makes the skill suspicious and high-risk to use, though not confirmed malware.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
May 1, 2026, 11:27 AM
Package URL
pkg:socket/skills-sh/borski%2Ftravel-hacking-toolkit%2Fchase-travel%2F@8e6ee98361327cebda9bed04c2e37146f38ae1f1
Security Audit — socket — chase-travel