duffel

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in publisher/data-flow alignment: it uses official Duffel endpoints, expected headers, and proportionate credentials for travel booking. However, it is HIGH RISK operationally because it enables autonomous real-world booking and cancellation actions and handles passenger PII, with a minor extra trust concern from the unverified optional `zero doctor` troubleshooting command.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 19, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fduffel%2F@0d94bdc82e082c8792638bece69542752e4464bc