mcpspend-cost-tracking
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The setup process uses
npxto download and execute the@mcpspend/proxypackage from the official NPM registry. - [COMMAND_EXECUTION]: The skill automates the modification of configuration files for AI clients such as Claude Desktop, Cursor, and Windsurf. It routes tool calls through the MCPSpend proxy and creates configuration backups (
.mcpspend.bak). - [DATA_EXFILTRATION]: Reports tool usage metadata (e.g., tool name, model used, latency) to
api.mcpspend.comfor centralized spend tracking. Documentation specifies that actual tool arguments and responses are not transmitted. - [SAFE]: All external resources, including the NPM packages and API domains, are verified as vendor-owned tools belonging to Aradotso and are necessary for the skill's core functionality.
Audit Metadata