leaderboard

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (the !command syntax) to execute a local Node.js script. This command runs automatically when the skill is loaded to provide visibility into the repository's token consumption. The execution uses platform environment variables (CLAUDE_SKILL_DIR and CLAUDE_PLUGIN_ROOT) to locate the context-hogs.js script within the tool's installation directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 03:49 PM
Security Audit — agent-trust-hub — leaderboard