cost-tracking

Fail

Audited by Socket on Apr 1, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core skill is mostly coherent for billing analysis and uses official Anthropic/Vercel APIs, but the optional Vantage MCP path is a meaningful trust and data-flow risk: it adds a third-party service, forwards high-privilege Anthropic admin credentials, and creates transitive integration risk not required for the stated purpose. No confirmed malware or hidden payloads are present, but the credential-forwarding and external MCP setup make this skill medium-high risk.

Confidence: 89%Severity: 72%
MalwareHIGH
.clawnet/unsigned-skill.json

High-risk supply-chain artifact. The embedded instructions describe a telemetry pipeline that collects token/billing/usage metrics using API credentials and forwards derived data to external webhook/collector endpoints. It also contains repeated adversarial/C2-style and credential-misuse framing that is inconsistent with benign cost tracking. Treat as unsafe and investigate/quarantine the real package contents, install scripts, and any runtime entrypoints.

Confidence: 80%Severity: 85%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fprompts%2Fcost-tracking%2F@f28641b4b75e267d2d589e5d011a2e82b4fa1229