cost-tracking
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
node -eto execute inline JavaScript for finding and reading the costs log file cross-platform.\n- [DYNAMIC_EXECUTION]: The skill generates and executes Node.js code at runtime to process JSONL data. The logic is based on static templates provided within the skill instructions.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a local JSONL file, which creates a vulnerability surface if the log content can be influenced by external actors or malicious inputs processed in previous sessions.\n - Ingestion points: Reads metrics from
~/.claude/metrics/costs.jsonlas defined in SKILL.md.\n - Boundary markers: The skill lacks delimiters or explicit instructions to ignore potential commands embedded within the data being processed.\n
- Capability inventory: The skill uses
node -ewhich allows for file system access and script execution output.\n - Sanitization: The processing scripts use
JSON.parse()andNumber()for structural and type validation but do not perform content-level sanitization or filtering of the string fields.
Audit Metadata