lov-check-balance

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/check_balance.py uses the subprocess.run function to execute the macOS security command. This is used legitimately to retrieve API keys and session tokens from the system Keychain when available.
  • [DATA_EXFILTRATION]: The skill reads sensitive credential files (e.g., ~/.codex/auth.json, ~/.claude/.credentials.json) and API keys from environment variables. It transmits these credentials to external endpoints to query balance information. However, all identified destinations are official API endpoints for the services being checked, such as chatgpt.com, api.anthropic.com, api.deepseek.com, and openrouter.ai. This behavior is necessary for the skill's primary function and follows the expected workflow for balance checking.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests untrusted external data from local LiteLLM gateway logs (JSONL format) and the cc-switch SQLite database.
  • Ingestion points: Reads requests-brief.jsonl and cc-switch.db from the user's home directory.
  • Boundary markers: The skill does not implement specific delimiters for the ingested log data, though the processing logic is strictly focused on numeric aggregation.
  • Capability inventory: The skill has the capability to execute subprocesses (keychain access) and perform network GET requests.
  • Sanitization: The script uses standard JSON and SQLite parsers to extract usage statistics. The risk is considered low as the data is primarily used for generating numeric reports and tables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:51 AM
Security Audit — agent-trust-hub — lov-check-balance