{"name":"io.github.MikkoParkkola/trvl","slug":"mikkoparkkola-trvl","title":"trvl","description":"Door-to-door travel MCP + CLI: flights, hotels, trains, cars, ferries. No API keys, Go binary.","url":"https://mcp.market/server/mikkoparkkola-trvl","rating":null,"grade":"D","score":49,"certified":false,"status":"active","category":"maps","tags":["maps"],"presence":{"score":48,"stars":77,"forks":5,"downloads_week":238,"last_push_at":"2026-09-19T06:45:37.000Z","license":"NOASSERTION"},"uptime":null,"claimed":false,"transport":"mixed","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/MikkoParkkola/trvl","website":"https://github.com/MikkoParkkola/trvl","version":"1.21.6","remotes":[],"packages":[{"registryType":"oci","identifier":"ghcr.io/mikkoparkkola/trvl:1.21.6","transport":{"type":"stdio"},"environmentVariables":[{"description":"Bearer token for HTTP-mode auth (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_TOKEN"},{"description":"Read-scoped bearer token for HTTP-mode auth (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_READ_TOKEN"},{"description":"Write-scoped bearer token for HTTP-mode auth (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_WRITE_TOKEN"},{"description":"OAuth token introspection endpoint for HTTP-mode auth (unused in stdio). Optional.","name":"TRVL_MCP_OAUTH_INTROSPECTION_URL"},{"description":"OAuth client ID for HTTP-mode token introspection (unused in stdio). Optional.","name":"TRVL_MCP_OAUTH_CLIENT_ID"},{"description":"OAuth client secret for HTTP-mode token introspection (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_OAUTH_CLIENT_SECRET"},{"description":"Expected OAuth audience for HTTP-mode token introspection (unused in stdio). Optional.","name":"TRVL_MCP_OAUTH_AUDIENCE"},{"description":"Selects which MCP tool set is registered (e.g. smart/full). Optional, defaults to full set.","name":"TRVL_MCP_TOOL_MODE"},{"description":"Per-tool-call timeout override. Optional, defaults to the built-in timeout.","name":"TRVL_MCP_TOOL_TIMEOUT"},{"description":"Air France-KLM API key; unlocks that airline's live fares/award search. Optional, trvl works without it.","isSecret":true,"name":"AFKLM_KEY"},{"description":"1Password reference for the Air France-KLM API key. Optional, alternative to AFKLM_KEY.","name":"AFKLM_OP_REF"},{"description":"macOS Keychain service name to read the Air France-KLM API key from. Optional, alternative to AFKLM_KEY.","name":"AFKLM_KEYCHAIN_SERVICE"},{"description":"Session cookies for Air France-KLM award search. Optional, unlocks award-fare lookups only.","isSecret":true,"name":"AFKL_KLM_COOKIES"},{"description":"SerpApi API key; unlocks search-engine-backed lookups used by some providers. Optional, trvl works without it.","isSecret":true,"name":"SERPAPI_KEY"},{"description":"Travelpayouts API token; unlocks that flight-price data source. Optional, trvl works without it.","isSecret":true,"name":"TRAVELPAYOUTS_TOKEN"},{"description":"Transavia API key; unlocks that airline's live fares. Optional, trvl works without it.","isSecret":true,"name":"TRANSAVIA_API_KEY"},{"description":"Ticketmaster API key; unlocks event listings for destinations. Optional, trvl works without it.","isSecret":true,"name":"TICKETMASTER_API_KEY"},{"description":"Foursquare API key; unlocks that place-search data source. Optional, trvl works without it.","isSecret":true,"name":"FOURSQUARE_API_KEY"},{"description":"OpenTripMap API key; unlocks that attractions data source. Optional, trvl works without it.","isSecret":true,"name":"OPENTRIPMAP_API_KEY"},{"description":"Geoapify API key; unlocks that places/geocoding data source. Optional, trvl works without it.","isSecret":true,"name":"GEOAPIFY_API_KEY"},{"description":"Distribusion API key; unlocks that ground-transport data source. Optional, trvl works without it.","isSecret":true,"name":"DISTRIBUSION_API_KEY"},{"description":"Skyscanner API key; unlocks that car-hire data source. Optional, trvl works without it.","isSecret":true,"name":"SKYSCANNER_API_KEY"}]},{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"trvl-mcp","version":"1.21.6","runtimeHint":"npx","transport":{"type":"stdio"},"environmentVariables":[{"description":"Bearer token for HTTP-mode auth (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_TOKEN"},{"description":"Read-scoped bearer token for HTTP-mode auth (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_READ_TOKEN"},{"description":"Write-scoped bearer token for HTTP-mode auth (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_WRITE_TOKEN"},{"description":"OAuth token introspection endpoint for HTTP-mode auth (unused in stdio). Optional.","name":"TRVL_MCP_OAUTH_INTROSPECTION_URL"},{"description":"OAuth client ID for HTTP-mode token introspection (unused in stdio). Optional.","name":"TRVL_MCP_OAUTH_CLIENT_ID"},{"description":"OAuth client secret for HTTP-mode token introspection (unused in stdio). Optional.","isSecret":true,"name":"TRVL_MCP_OAUTH_CLIENT_SECRET"},{"description":"Expected OAuth audience for HTTP-mode token introspection (unused in stdio). Optional.","name":"TRVL_MCP_OAUTH_AUDIENCE"},{"description":"Selects which MCP tool set is registered (e.g. smart/full). Optional, defaults to full set.","name":"TRVL_MCP_TOOL_MODE"},{"description":"Per-tool-call timeout override. Optional, defaults to the built-in timeout.","name":"TRVL_MCP_TOOL_TIMEOUT"},{"description":"Air France-KLM API key; unlocks that airline's live fares/award search. Optional, trvl works without it.","isSecret":true,"name":"AFKLM_KEY"},{"description":"1Password reference for the Air France-KLM API key. Optional, alternative to AFKLM_KEY.","name":"AFKLM_OP_REF"},{"description":"macOS Keychain service name to read the Air France-KLM API key from. Optional, alternative to AFKLM_KEY.","name":"AFKLM_KEYCHAIN_SERVICE"},{"description":"Session cookies for Air France-KLM award search. Optional, unlocks award-fare lookups only.","isSecret":true,"name":"AFKL_KLM_COOKIES"},{"description":"SerpApi API key; unlocks search-engine-backed lookups used by some providers. Optional, trvl works without it.","isSecret":true,"name":"SERPAPI_KEY"},{"description":"Travelpayouts API token; unlocks that flight-price data source. Optional, trvl works without it.","isSecret":true,"name":"TRAVELPAYOUTS_TOKEN"},{"description":"Transavia API key; unlocks that airline's live fares. Optional, trvl works without it.","isSecret":true,"name":"TRANSAVIA_API_KEY"},{"description":"Ticketmaster API key; unlocks event listings for destinations. Optional, trvl works without it.","isSecret":true,"name":"TICKETMASTER_API_KEY"},{"description":"Foursquare API key; unlocks that place-search data source. Optional, trvl works without it.","isSecret":true,"name":"FOURSQUARE_API_KEY"},{"description":"OpenTripMap API key; unlocks that attractions data source. Optional, trvl works without it.","isSecret":true,"name":"OPENTRIPMAP_API_KEY"},{"description":"Geoapify API key; unlocks that places/geocoding data source. Optional, trvl works without it.","isSecret":true,"name":"GEOAPIFY_API_KEY"},{"description":"Distribusion API key; unlocks that ground-transport data source. Optional, trvl works without it.","isSecret":true,"name":"DISTRIBUSION_API_KEY"},{"description":"Skyscanner API key; unlocks that car-hire data source. Optional, trvl works without it.","isSecret":true,"name":"SKYSCANNER_API_KEY"}]}],"tools":[],"scan":{"score":49,"grade":"D","scanned_at":"2026-09-19T21:32:16.652Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-19T21:32:16.670Z","components":{"code":{"score":3,"max":25,"notes":["3 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 1 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"install.script","severity":"medium","component":"code","title":"npm install lifecycle script present"},{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"bin/install.js: …ich is available since Windows 10 execSync(`tar -xzf \"${tmpFile}\" -C \"${binDir}\" trvl.exe`, { stdio: \"pipe\" }); …"},{"id":"install.script","severity":"medium","component":"code","title":"npm install lifecycle script present","evidence":"package.json: …in/trvl-mcp.js\" }, \"scripts\": { \"postinstall\": \"node bin/install.js\" }, \"os\": [ …"}],"inputs":{"packages":[{"registryType":"npm","identifier":"trvl-mcp","version":"1.21.6","found":true,"license":"PolyForm-Noncommercial-1.0.0","hasInstallScripts":true,"dependencyCount":0,"publishedAt":"2026-09-10T17:34:09.940Z","repositoryUrl":"git+https://github.com/MikkoParkkola/trvl.git","weeklyDownloads":238}],"repo":{"found":true,"owner":"MikkoParkkola","repo":"trvl","archived":false,"pushedAt":"2026-09-19T06:45:37Z","stars":77,"forks":5,"openIssues":1,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/78788115?v=4","ownerCreatedAt":"2021-02-09T08:10:14Z","license":"NOASSERTION"},"icon":{"url":"https://avatars.githubusercontent.com/u/78788115?v=4&s=128","source":"registry"},"presence":{"stars":77,"forks":5,"downloadsWeek":238,"license":"NOASSERTION","lastPushAt":"2026-09-19T06:45:37.000Z","score":48}}}},"grade_history":[],"reviews":[]}