token-tracker

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a vendor-provided library netclaw_tokens located in src/netclaw_tokens/. No arbitrary shell commands or remote code execution patterns were detected.
  • [CREDENTIALS_UNSAFE]: The skill utilizes the ANTHROPIC_API_KEY environment variable. This is a documented, standard credential for the host platform used as intended for token counting via the Anthropic API.
  • [PROMPT_INJECTION]: The skill contains instructions for the agent to append a mandatory footer to its responses. These instructions are consistent with the utility's purpose and do not attempt to bypass safety guidelines or override core agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:07 AM
Security Audit — agent-trust-hub — token-tracker