ecomode

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines internal routing rules to prioritize cost-efficient model tiers. This logic is contained within the prompt instructions and does not involve external dependencies.
  • [SAFE]: The instruction to read 'docs/shared/agent-tiers.md' is a standard operation to retrieve local configuration or guidance data from the platform's shared environment.
  • [COMMAND_EXECUTION]: The skill uses platform-specific MCP tools ('state_write', 'state_clear') and a '$cancel' command for lifecycle management. These are standard features for managing the state of an agent modifier and do not represent unauthorized or malicious command execution.
  • [DATA_EXFILTRATION]: While the skill mentions a configuration path '~/.codex/.rcs-config.json', it does so in a documentation context to explain how a user can manually disable the skill. There are no instructions for the agent to exfiltrate or modify this file maliciously.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:36 AM
Security Audit — agent-trust-hub — ecomode