Back to plugin

Security audit

OctoTrip Flights

Security checks for vulnerabilities and agentic risk

Overview

This package is a clearly scoped remote flight-search MCP integration with disclosed affiliate links and no local code or credential access in the inspected artifacts.

Before installing, understand that flight searches will be sent to OctoTrip's remote MCP service and returned booking links may include affiliate attribution. The package does not show local code execution or credential access, but you should still avoid entering sensitive personal details beyond what is needed to search flights.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.