context-budget

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the local environment, performing read-only analysis of project components such as agents, skills, rules, and MCP configurations. No network exfiltration, sensitive credential access, or unauthorized file modification patterns were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans external content from project files (agents, skills, rules) to calculate token usage.
  • Ingestion points: Reads agents/*.md, skills/*/SKILL.md, rules/**/*.md, and CLAUDE.md files from the project directory.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Limited to file reading and reporting; no subprocess execution, network operations, or file-write capabilities are employed.
  • Sanitization: None detected; however, the skill only performs counting and estimation (words, lines, tools) rather than interpreting or executing the file contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — context-budget