pp-travelclick
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core hotel-rate lookup purpose mostly matches the capabilities and official TravelClick endpoint usage, and the install sources are verifiably tied to the same publisher. The main concerns are credential forwarding of a manually captured bearer token into third-party CLI code, arbitrary webhook output delivery, unpinned external installs, and transitive MCP installation. This is not confirmed malware, but it has meaningful security risk beyond a narrowly scoped read-only API helper.
Confidence: 87%Severity: 64%
Audit Metadata