session-usage
Warn
Audited by Socket on Aug 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's goal is coherent, but it achieves it by directly extracting Claude OAuth credentials and forwarding them through a third-party CLI to an undocumented Anthropic endpoint. No clear off-domain exfiltration or malware behavior is present, yet the credential handling and undocumented API use make the security posture disproportionate for a simple usage-check skill.
Confidence: 87%Severity: 64%
Audit Metadata