cancel-booking

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, but it delegates a destructive booking cancellation to an unpinned, externally fetched npm CLI whose publisher and official relationship to a real travel service were not verified. The main risk is supply-chain trust plus forwarding user PII to opaque third-party code for a real-world action.

Confidence: 86%Severity: 79%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/JustinTravala%2Ftravel-skills%2Fcancel-booking%2F@f0908de5ca214a78d07c3edb92b5795ae9214785