cco-overhead

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local script overhead.js from the plugin's source directory using the Bash tool to generate reports on token usage and tool activity.
  • [DATA_EXFILTRATION]: It accesses local project files (CLAUDE.md) and session transcript metadata to itemize context costs. This data is used solely for local reporting and optimization recommendations.
  • [PROMPT_INJECTION]: The instructions include a safety requirement that the agent must only execute tool removal commands if the user explicitly agrees after reviewing the audit report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:48 AM
Security Audit — agent-trust-hub — cco-overhead