kmp-token-saver
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (e.g.,
scripts/install-rtk.sh,scripts/install-headroom.sh, andscripts/install-ponytail.sh) that execute system-level commands such asbrew install,pip install, andclaude plugin installto configure the host environment. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of software from third-party repositories and registries (GitHub, Pip, Homebrew) for tools like RTK, Headroom, and Ponytail. These represent unverified external dependencies from non-trusted vendors.
- [PERSISTENCE]: The skill automates persistent, global changes to the agent environment. Specifically,
scripts/install-ponytail.shinstalls a plugin at the user scope, and theRTKtool requires wiring aPreToolUsehook into~/.claude/settings.json, which affects all future sessions. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and compress external data including tool output, logs, files, and RAG chunks. This creates an attack surface where instructions embedded in the processed data could influence the agent's behavior.
- [REMOTE_CODE_EXECUTION]: The documentation in
SKILL.mdandreferences/token-saving-tools.mdreferences a high-risk remote code execution vector in the Caveman tool's installation method (curl | bash). However, the skill explicitly instructs the agent not to run this command directly, requiring user intervention instead.
Audit Metadata