cost-tracking

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes bash for prerequisite checks and the sqlite3 utility to execute SQL queries against a local database file.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from a local database file, which constitutes an ingestion point for potentially untrusted data. 1. Ingestion points: ~/.claude-cost-tracker/usage.db (accessed via sqlite3). 2. Boundary markers: Absent; database query results are not wrapped in delimiters or safety warnings. 3. Capability inventory: The skill can execute shell commands (sqlite3) and read local files. 4. Sanitization: Absent; the skill does not perform validation or escaping of database content before including it in the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — cost-tracking