usage-tracker

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
references/log-usage.sh

This module is best characterized as a local usage/telemetry logger. It does not show overt malware behaviors (no networking, no dynamic execution, no obvious exfiltration). The main security concerns are (1) privacy-sensitive logging of derived user request content to a persistent JSONL file, and (2) the ability to read an arbitrary existing file path when `transcript_path` is attacker-influenced (within the executing user’s permissions). Additionally, delimiter-based field extraction could cause incorrect logging if injected data contains the custom separator, though it does not appear to enable code execution within this snippet.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:04 AM
Package URL
pkg:socket/skills-sh/j4rk0r%2Fclaude-skills%2Fusage-tracker%2F@4f89c2519addcd2f12c831f596f12fd41a9af311