southwest

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core function is coherent with fare scraping, but it relies on anti-detection browser evasion, a third-party container/image chain, and optional forwarding of Southwest account credentials into that code. Data flow is mostly direct to southwest.com with no obvious exfiltration endpoint, so this is not confirmed malware, but it is a high-trust automation skill with meaningful supply-chain and credential-handling risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 1, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/borski%2Ftravel-hacking-toolkit%2Fsouthwest%2F@5b9e518c32db891f88deebb1e6611aafc0aab736
Security Audit — socket — southwest