cost-budget-check
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute a local Node.js script atplugins/ruflo-cost-tracker/scripts/budget.mjs. It supports subcommands for checking, setting, and retrieving budget data. - [INDIRECT_PROMPT_INJECTION]: The skill processes session-based cost data from memory, which acts as a potential surface for indirect prompt injection.
- Ingestion points: Cost records are retrieved from memory storage keys
cost-tracking:budget-configandcost-tracking:session-*as referenced in SKILL.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially embedded malicious content within the cost data.
- Capability inventory: The skill has access to the
Bashtool for script execution and memory tools for data retrieval. - Sanitization: The skill documentation does not mention any sanitization, filtering, or validation performed on the cost records before they are presented to the agent.
Audit Metadata