pay-and-book

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it still carries meaningful risk because it enables autonomous real-world booking/payment, uses mutable `npx` execution, and instructs transitive installation of Coinbase wallet skills through the Skills CLI. No clear evidence of credential theft or covert exfiltration is present from the provided content.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 4, 2026, 03:23 AM
Package URL
pkg:socket/skills-sh/JustinTravala%2Ftravel-skills%2Fpay-and-book%2F@e0109ef2574087a69dac5105798e6fd009453b5d