search-room

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent and scope is narrow, but it relies on an unpinned `npx` execution path for a not-clearly-verified publisher/package and hides the actual backend data flow inside the CLI. No clear signs of credential harvesting or malicious behavior, but install trust is only medium.

Confidence: 78%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/JustinTravala%2Ftravel-skills%2Fsearch-room%2F@efdbaebab3b68bdb72049c84ba32855d60d8355d