manage-booking

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to download and execute the @tvl-justin/travel-cli package. Based on the vendor name 'justintravala' mentioned in the context, this is a recognized vendor resource and does not present a security risk in itself.
  • [COMMAND_EXECUTION]: The skill executes a CLI command (manage-booking) to interface with a remote travel API. The command is constrained to retrieving data based on user-provided identifiers.
  • [SAFE]: No malicious patterns such as credential theft, prompt injection, or obfuscation were detected. The use of npx for a vendor-specific CLI is standard behavior for this type of integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:01 PM
Security Audit — agent-trust-hub — manage-booking