concierge

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s features mostly align with a travel concierge, and key installs shown are from official sources, but it has a high-risk footprint due to autonomous phone calls, broad third-party credential forwarding, local storage of customer PII/secrets, and auto-exposed call infrastructure. The main concern is risky autonomy and expanded trust boundaries, not confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:58 PM
Package URL
pkg:socket/skills-sh/skillhq%2Ftravel-concierge%2Fconcierge%2F@8eeeb3ae64e60de8200754bc5df0cbc0b465ddc8