cco-overhead
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local script
overhead.jsfrom the plugin's source directory using the Bash tool to generate reports on token usage and tool activity. - [DATA_EXFILTRATION]: It accesses local project files (CLAUDE.md) and session transcript metadata to itemize context costs. This data is used solely for local reporting and optimization recommendations.
- [PROMPT_INJECTION]: The instructions include a safety requirement that the agent must only execute tool removal commands if the user explicitly agrees after reviewing the audit report.
Audit Metadata