cost-tracking

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional, providing best practices for implementing cost-tracking logic within an application. It promotes secure practices such as using idempotency keys for ledgering and versioning pricing data to prevent silent mis-billing.
  • [COMMAND_EXECUTION]: The file scripts/verify.sh is a local Bash script used as a linter for configuration files. It utilizes standard Unix utilities (grep, awk, wc) to check for required metadata in project files. The script is read-only, does not perform network requests, and does not access sensitive system directories.
  • [EXTERNAL_DOWNLOADS]: The documentation references several official service provider domains (e.g., Anthropic, OpenAI, AWS, GCP) and reputable technology blogs for pricing information and technical documentation. These are static references for human users and do not trigger automated runtime downloads or external code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:38 PM
Security Audit — agent-trust-hub — cost-tracking