cost-tracking

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill is largely aligned with cost tracking and mostly uses official Anthropic and Vercel billing endpoints, but it introduces medium-high risk through an optional third-party Vantage MCP path that forwards high-value billing credentials and data outside official service APIs. The `npx ccusage@latest` path is also unpinned supply-chain risk. No confirmed malware or clear exfiltration beyond the disclosed third-party dashboard flow.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/b-open-io%2Fprompts%2Fcost-tracking%2F@d1320365f14074c24e37d7074cfaaf859c22c2d1