skills/ruvnet/ruflo/cost-budget-check/Gen Agent Trust Hub

cost-budget-check

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local Node.js script at plugins/ruflo-cost-tracker/scripts/budget.mjs. It supports subcommands for checking, setting, and retrieving budget data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session-based cost data from memory, which acts as a potential surface for indirect prompt injection.
  • Ingestion points: Cost records are retrieved from memory storage keys cost-tracking:budget-config and cost-tracking:session-* as referenced in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially embedded malicious content within the cost data.
  • Capability inventory: The skill has access to the Bash tool for script execution and memory tools for data retrieval.
  • Sanitization: The skill documentation does not mention any sanitization, filtering, or validation performed on the cost records before they are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — cost-budget-check