token-tracker

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (scripts/token-analyzer.py) to process and report on token usage data.\n- [COMMAND_EXECUTION]: It uses the standard Python HTTP server module (python3 -m http.server) to host a local dashboard for data visualization.\n- [COMMAND_EXECUTION]: System commands like cat are used to read configuration, and open is used to launch the dashboard in a browser.\n- [EXTERNAL_DOWNLOADS]: The dashboard is documented to load Chart.js from a public CDN, which is a common and safe practice for web-based visualizations.\n- [SAFE]: Usage logs and budget settings are stored in application-specific directories (~/.forgewright/ and .forgewright/), adhering to the skill's intended purpose of tracking usage history.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — token-tracker