quota-reporter
Warn
Audited by Socket on May 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose understates the real footprint: this skill continuously handles sensitive local auth, uploads it to a custom cloud pool on arbitrary Vercel infrastructure, stores a reusable personal token, and installs replacement credentials fetched from that pool. Even without code, the data flows and permissions are fundamentally high risk and poorly aligned with a simple quota-reporting claim.
Confidence: 88%Severity: 91%
Audit Metadata