quotient-api

Warn

Audited by Socket on Jul 13, 2026

1 alert found:

Anomaly
AnomalyLOW
skill.md

SUSPICIOUS: the core Quotient API access pattern is mostly coherent and uses expected official-looking domains, but the skill expands trust to a third-party signer (Bankr) and encourages forwarding a privileged API key there. The optional agent-run signup/login flow also increases scope beyond simple API consumption. Main risk is disproportionate credential forwarding and broadened trust boundaries, not confirmed malware.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Jul 13, 2026, 05:50 PM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2Fquotient-api%2F@3f8dff587178b3ec8a2cd2ad7fac676145a05ee7077a9b833c831759a44e9bc2
Security Audit — socket — quotient-api