cohere-cost-tuning

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is instructional in nature, providing best practices for Cohere API cost management without any malicious intent or hidden behaviors. It correctly advises the use of environment variables or official dashboards for credential management.\n- [EXTERNAL_DOWNLOADS]: The code examples reference the official cohere-ai SDK for Node.js, which is a standard library for interacting with Cohere's services.\n- [INDIRECT_PROMPT_INJECTION]: The skill contains logic for processing untrusted external data.\n
  • Ingestion points: message parameter in budgetedChat and corpus array in cheapRAG within SKILL.md.\n
  • Boundary markers: Absent in the provided code snippets.\n
  • Capability inventory: Includes network API calls to Cohere via cohere.chat, cohere.embed, and cohere.rerank.\n
  • Sanitization: Absent.\n This surface is a functional requirement for the skill's purpose and does not include instructions to bypass safety guardrails or perform unauthorized actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:15 PM
Security Audit — agent-trust-hub — cohere-cost-tuning