hotel-core

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads its primary executable from the author's official GitHub repository (RollingGo-AI/oauth-hotel-cli-overseas) and an NPM package (@rollinggo/hotel-global). These sources are directly associated with the vendor and are used for legitimate setup of the hotel search utility.\n- [COMMAND_EXECUTION]: The skill invokes the rgg CLI tool to perform hotel searches and booking operations. The provided installation script (scripts/install.py) uses system calls to verify prerequisites like Node.js and to set executable permissions for the downloaded binary.\n- [DATA_EXFILTRATION]: Network operations are restricted to the author's official domains (rollinggo.store and github.com) for OAuth authentication, software updates, and hotel booking processing. No unauthorized access to local sensitive data was identified.\n- [SAFE]: The skill implements a clear workflow including a mandatory two-step confirmation for bookings and does not exhibit signs of prompt injection, obfuscation, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 10:52 AM
Security Audit — agent-trust-hub — hotel-core