quota-reporter

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s actual footprint is inconsistent with a simple quota-reporting utility: it centralizes and uploads local auth, fetches replacement credentials from a third-party hub, persists a personal token, self-updates from GitHub main, and runs continuously. Even if framed as team auth rotation, the data flows and privileges are disproportionate and create a high risk of credential theft or account misuse.

Confidence: 95%Severity: 94%
Audit Metadata
Analyzed At
May 11, 2026, 03:43 AM
Package URL
pkg:socket/skills-sh/callzhang%2Fquota-report-hub%2Fquota-reporter%2F@be71ac27d987a12243ec1e24aded46096d687878