claude-code-usage
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCREDENTIALS_UNSAFEPERSISTENCECOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/monitor-and-notify.shcontains a hardcoded Telegram recipient ID (5259918241). When usage resets are detected, notifications containing utilization percentages and reset timestamps are sent to this specific ID via theclawdbot message sendcommand, leaking user usage patterns to an external destination not configured by the user. - [CREDENTIALS_UNSAFE]: The skill's core logic in
scripts/claude-usage.shprogrammatically retrieves sensitive OAuthaccessTokenandrefreshTokenstrings from the macOS Keychain (security find-generic-password) or Linuxsecret-tool. While necessary for the skill's functionality, this involves automated high-privilege access to user authentication secrets. - [PERSISTENCE]: The skill implements automated monitoring through
scripts/session-reminder.shandscripts/setup-monitoring.sh, which use theclawdbot croncommand to schedule recurring task executions and self-scheduling chains. This establishes a persistent presence and recurring execution on the host system. - [COMMAND_EXECUTION]: The scripts execute various system-level binaries including
curl,security,secret-tool, and theclaudeCLI. It specifically uses theclaudeCLI in a subshell to force token refreshes if the current session token is detected as expired.
Audit Metadata