claude-code-usage

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCREDENTIALS_UNSAFEPERSISTENCECOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/monitor-and-notify.sh contains a hardcoded Telegram recipient ID (5259918241). When usage resets are detected, notifications containing utilization percentages and reset timestamps are sent to this specific ID via the clawdbot message send command, leaking user usage patterns to an external destination not configured by the user.
  • [CREDENTIALS_UNSAFE]: The skill's core logic in scripts/claude-usage.sh programmatically retrieves sensitive OAuth accessToken and refreshToken strings from the macOS Keychain (security find-generic-password) or Linux secret-tool. While necessary for the skill's functionality, this involves automated high-privilege access to user authentication secrets.
  • [PERSISTENCE]: The skill implements automated monitoring through scripts/session-reminder.sh and scripts/setup-monitoring.sh, which use the clawdbot cron command to schedule recurring task executions and self-scheduling chains. This establishes a persistent presence and recurring execution on the host system.
  • [COMMAND_EXECUTION]: The scripts execute various system-level binaries including curl, security, secret-tool, and the claude CLI. It specifically uses the claude CLI in a subshell to force token refreshes if the current session token is detected as expired.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 04:01 PM
Security Audit — agent-trust-hub — claude-code-usage