This flight-booking skill matches its stated purpose, but it handles real ticket actions, login keys, and passenger identity data with unsafe transport, storage, and confirmation practices.
Review carefully before installing. This skill can submit bookings, cancellations, changes, and refunds, and it handles passenger names, phone numbers, ID numbers, order IDs, ticket IDs, and an API key. The publisher should restore normal HTTPS certificate verification, stop storing auth keys in temp storage, mask PII in outputs, remove raw debug prints, document network and persistence behavior, and require explicit confirmation immediately before every order-affecting action.