mcpspend-cost-tracking

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The setup process uses npx to download and execute the @mcpspend/proxy package from the official NPM registry.
  • [COMMAND_EXECUTION]: The skill automates the modification of configuration files for AI clients such as Claude Desktop, Cursor, and Windsurf. It routes tool calls through the MCPSpend proxy and creates configuration backups (.mcpspend.bak).
  • [DATA_EXFILTRATION]: Reports tool usage metadata (e.g., tool name, model used, latency) to api.mcpspend.com for centralized spend tracking. Documentation specifies that actual tool arguments and responses are not transmitted.
  • [SAFE]: All external resources, including the NPM packages and API domains, are verified as vendor-owned tools belonging to Aradotso and are necessary for the skill's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 01:04 AM
Security Audit — agent-trust-hub — mcpspend-cost-tracking