quota-reporter

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose understates the real footprint: this skill continuously handles sensitive local auth, uploads it to a custom cloud pool on arbitrary Vercel infrastructure, stores a reusable personal token, and installs replacement credentials fetched from that pool. Even without code, the data flows and permissions are fundamentally high risk and poorly aligned with a simple quota-reporting claim.

Confidence: 88%Severity: 91%
Audit Metadata
Analyzed At
May 8, 2026, 01:26 AM
Package URL
pkg:socket/skills-sh/callzhang%2Fquota-report-hub%2Fquota-reporter%2F@29bc4a07defb84f22a35eeec79b3f8d1887220eb