token-cost-analyzer

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and implementation templates for cost tracking, reporting, and calculation logic. All logic is self-contained within markdown code blocks and does not perform network operations, access sensitive files, or execute external scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for assessing task complexity using user-provided strings and constructing prompts through variable interpolation. Ingestion points: User inputs processed by assessedComplexity and prompt templates in SKILL.md. Boundary markers: None. Capability inventory: The skill does not utilize any tools, network access, or file system permissions. Sanitization: None. This is a common design pattern for cost-saving prompt generation and poses no security risk due to the lack of exploitable capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 01:19 PM
Security Audit — agent-trust-hub — token-cost-analyzer