kmp-token-saver

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (e.g., scripts/install-rtk.sh, scripts/install-headroom.sh, and scripts/install-ponytail.sh) that execute system-level commands such as brew install, pip install, and claude plugin install to configure the host environment.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of software from third-party repositories and registries (GitHub, Pip, Homebrew) for tools like RTK, Headroom, and Ponytail. These represent unverified external dependencies from non-trusted vendors.
  • [PERSISTENCE]: The skill automates persistent, global changes to the agent environment. Specifically, scripts/install-ponytail.sh installs a plugin at the user scope, and the RTK tool requires wiring a PreToolUse hook into ~/.claude/settings.json, which affects all future sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and compress external data including tool output, logs, files, and RAG chunks. This creates an attack surface where instructions embedded in the processed data could influence the agent's behavior.
  • [REMOTE_CODE_EXECUTION]: The documentation in SKILL.md and references/token-saving-tools.md references a high-risk remote code execution vector in the Caveman tool's installation method (curl | bash). However, the skill explicitly instructs the agent not to run this command directly, requiring user intervention instead.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 11:35 PM
Security Audit — agent-trust-hub — kmp-token-saver