quotient-api
Warn
Audited by Socket on Jul 13, 2026
1 alert found:
AnomalyAnomalyskill.md
LOWAnomalyLOW
skill.md
SUSPICIOUS: the core Quotient API access pattern is mostly coherent and uses expected official-looking domains, but the skill expands trust to a third-party signer (Bankr) and encourages forwarding a privileged API key there. The optional agent-run signup/login flow also increases scope beyond simple API consumption. Main risk is disproportionate credential forwarding and broadened trust boundaries, not confirmed malware.
Confidence: 84%Severity: 57%
Audit Metadata