pp-travelclick

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core hotel-rate lookup purpose mostly matches the capabilities and official TravelClick endpoint usage, and the install sources are verifiably tied to the same publisher. The main concerns are credential forwarding of a manually captured bearer token into third-party CLI code, arbitrary webhook output delivery, unpinned external installs, and transitive MCP installation. This is not confirmed malware, but it has meaningful security risk beyond a narrowly scoped read-only API helper.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Aug 31, 2026, 11:01 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-travelclick%2F@3811622f6cdd4aba55b1797d14c0758823112bccd59660c2cc51baeb2023023b
Security Audit — socket — pp-travelclick