flightclaw

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, flightclaw presents a coherent tool for local flight price tracking with optional MCP server integration. The footprint is generally aligned with the stated purpose, but several risk factors warrant attention: reliance on external installation sources (GitHub/NPM/PyPI), local data persistence without explicit security controls, and privacy implications from currency determination and potential location data usage. If deployed in a trusted environment with verified sources, proper data governance, and authentication for MCP endpoints, the risk remains moderate with no clear evidence of active malice in the fragment itself.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fflightclaw%2F@9b6f6c683f910c614a14cf4fff4c376220c4ac97