cache-guard
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
audit-session.mjsscript processes session transcripts that may contain untrusted data from conversation history. - Ingestion points: Reads
.jsonltranscript files from the~/.claude/projects/directory. - Boundary markers: Data is processed as line-delimited JSON objects.
- Capability inventory: The script is limited to read-only operations and printing results to the terminal; no network, file-write, or command-execution capabilities are present.
- Sanitization: Uses
JSON.parse()to handle data and strictly accesses specific metadata fields (usage,timestamp,type) for reporting. - [DATA_EXFILTRATION]: The audit utility reads the user's local conversation history from the Claude Code configuration directory (
~/.claude/projects/) to analyze token consumption. The analysis is performed entirely on the local machine, and the script contains no network functionality or external communication to exfiltrate this data. - [EXTERNAL_DOWNLOADS]: The installation process involves cloning the skill from the author's repository on GitHub (
github.com/0x0funky/claude-cache-guard), which is consistent with the skill's source and intended deployment for Claude Code.
Audit Metadata