travelport

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated Travelport integration purpose and uses an official npm-distributed vendor CLI, so it does not look outright malicious. However, all Travelport access is mediated through Membrane, meaning credentials and data may be handled by a third-party proxy/service rather than directly by Travelport; this is a real trust and data-flow concern, though disclosed and proportionate to the product design.

Confidence: 88%Severity: 57%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftravelport%2F@3fdf87a9d71a3a31e8557eb8f50f0286546a79ad