ops-costs

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill aggregates data by calling run.sh in sibling skill directories using subprocess.run. This execution is restricted to a predefined list of provider skills, and parameters are either hardcoded or validated.
  • [EXTERNAL_DOWNLOADS]: Dependency installation is performed via uv from the official Python Package Index (PyPI) during initialization.
  • [SAFE]: Analysis of the source code and metadata revealed no evidence of prompt injection, data exfiltration, or obfuscation. The data processed from external tools is sanitized via JSON parsing and numeric conversion before display.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — ops-costs