quotient

Warn

Audited by Socket on Sep 9, 2026

4 alerts found:

Anomalyx4
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its purpose: paid Quotient intelligence plus Bankr handoff for market actions. However, it combines real-money payments, portfolio reads, and trade execution through third-party infrastructure, forwards sensitive Bankr credentials to external tooling, and relies on a Render-hosted API gateway instead of a first-party Quotient domain. This is not confirmed malware, but the financial-action scope and external trust chain make it higher risk than a normal read-only documentation skill.

Confidence: 90%Severity: 58%
AnomalyLOW
scripts/signal-strategy.mjs

This fragment implements an intentionally interactive and policy-controlled Polymarket trading workflow. It contains external network calls, local state writes, subprocess execution, paid API access, and real trade submission, so it presents meaningful operational and financial risk. However, the visible code includes strong validation, allowlisting, spending caps, previews, short-lived approvals, plan hashing, re-quoting, and post-trade verification. No clear credential theft, covert exfiltration, persistence, sabotage, obfuscation, or other malicious supply-chain behavior is evident. Assessment is limited to the shown fragment and referenced external tools/configuration.

Confidence: 93%Severity: 58%
AnomalyLOW
references/vanilla-x402-flow.md

The fragment appears to implement a legitimate managed-wallet x402 payment integration, not obvious malware. However, it forwards server-controlled typed data to a signing API without visible pre-sign validation, and it contains a significant chain-ID mismatch between the documented USDG requirement (eip155:4663) and the configured client (eip155:8453). The destination URL and payment parameters should be allowlisted and validated before signing, and settlement should be independently verified. Because only a fragment is shown, the presence of validation elsewhere cannot be established from this code.

Confidence: 91%Severity: 67%
AnomalyLOW
catalog.json

No direct malicious behavior is present in the supplied JSON metadata. It is a configuration for a financially sensitive skill that installs code from an external repository and may handle API keys, OTPs, cryptocurrency payments, and trade execution. The referenced repository and scripts must be reviewed before use, and read-write credentials and autopay should not be enabled without trust verification.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fquotient%2F@61dc7475fc3edb69023bc04d08ac2733ddea1430f83f1b94fe2a598b4f98cb41
Security Audit — socket — quotient