Trust Assessment
amadeus-hotels received a trust score of 62/100, placing it in the Caution category. This skill has some security considerations that users should review before deployment.
SkillShield's automated analysis identified 6 findings: 0 critical, 0 high, 5 medium, and 1 low severity. Key findings include Suspicious import: requests, Unpinned Dependency in Manifest.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. The Static Code Analysis layer scored lowest at 65/100, indicating areas for improvement.
Last analyzed on February 14, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings6
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Suspicious import: requests Import of 'requests' detected. This module provides network or low-level system access. Verify this import is necessary. Network and system modules in skill code may indicate data exfiltration. | Static | skills/kesslerio/amadeus-hotels/scripts/auth.py:12 | |
| MEDIUM | Suspicious import: requests Import of 'requests' detected. This module provides network or low-level system access. Verify this import is necessary. Network and system modules in skill code may indicate data exfiltration. | Static | skills/kesslerio/amadeus-hotels/scripts/details.py:12 | |
| MEDIUM | Suspicious import: requests Import of 'requests' detected. This module provides network or low-level system access. Verify this import is necessary. Network and system modules in skill code may indicate data exfiltration. | Static | skills/kesslerio/amadeus-hotels/scripts/offers.py:13 | |
| MEDIUM | Suspicious import: requests Import of 'requests' detected. This module provides network or low-level system access. Verify this import is necessary. Network and system modules in skill code may indicate data exfiltration. | Static | skills/kesslerio/amadeus-hotels/scripts/search.py:12 | |
| MEDIUM | Suspicious import: requests Import of 'requests' detected. This module provides network or low-level system access. Verify this import is necessary. Network and system modules in skill code may indicate data exfiltration. | Static | skills/kesslerio/amadeus-hotels/scripts/track.py:14 | |
| LOW | Unpinned Dependency in Manifest The skill's manifest specifies 'requests' as a dependency without pinning a specific version. This can lead to non-deterministic builds, potential compatibility issues, or the introduction of vulnerabilities if a future version of 'requests' contains a security flaw or breaking change. It is best practice to pin dependencies to exact versions. Pin the 'requests' dependency to a specific version (e.g., 'requests==2.28.1') in the manifest. Regularly review and update pinned dependencies. | LLM | SKILL.md:10 |
Scan History
Embed Code
[](https://skillshield.io/report/d382c8389add0014)
Powered by SkillShield