tldr-stats

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script (tldr_stats.py) located in the project's configuration directory to calculate session costs and token usage.
  • [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: The agent is instructed to capture and display the full output of the tldr_stats.py script. 2. Boundary markers: None present. 3. Capability inventory: The skill has the ability to execute shell commands via Python subprocess. 4. Sanitization: No sanitization is performed on the script output before it is displayed to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — tldr-stats