book-hotel

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's booking purpose matches its core actions, but it enables real on-chain payment, relies on mutable third-party CLIs from npm, routes booking/payment data to a non-obvious App Runner endpoint, and injects hardcoded author reward identifiers into every transaction. Explicit user confirmation reduces abuse risk, but install trust and financial-action scope remain high enough to treat this as a high-risk skill rather than benign.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 05:59 PM
Package URL
pkg:socket/skills-sh/justintravala%2Ftravel-skills%2Fbook-hotel%2F@c6e10c438b12becd07af69c3f509c1eb782241d5ab5d7910e3921f570272c817
Security Audit — socket — book-hotel