session-usage

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's goal is coherent, but it achieves it by directly extracting Claude OAuth credentials and forwarding them through a third-party CLI to an undocumented Anthropic endpoint. No clear off-domain exfiltration or malware behavior is present, yet the credential handling and undocumented API use make the security posture disproportionate for a simple usage-check skill.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Aug 5, 2026, 10:42 AM
Package URL
pkg:socket/skills-sh/fuzzyfox%2Fskills%2Fsession-usage%2F@5f3a27926fc87736b8fb3167efb0576034c068a084984c439f5135f5273b9189
Security Audit — socket — session-usage