search-room

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill leverages npx to download and execute the @tvl-justin/travel-cli package at runtime. This package is part of the developer's own toolset as defined in the vendor context.
  • [COMMAND_EXECUTION]: The skill executes shell commands using the npx utility to interact with the travel API. These commands are limited to the intended functionality of retrieving hotel packages.
  • [DATA_EXFILTRATION]: The skill transmits a sessionId and hotelId to the CLI tool. This is a standard requirement for maintaining state between the search and room selection phases of the travel booking process within the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:42 AM