cost-export
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to transmit internal cost-tracking records from the AgentDB to external URLs via a user-specified webhook argument. This provides a mechanism for exporting data to non-whitelisted external domains.
- [PRIVILEGE_ESCALATION]: The skill documentation suggests writing Prometheus metrics to
/var/lib/node_exporter/textfile_collector/. On standard Linux systems, the/var/lib/directory is restricted and typically requires root or specific service user privileges to write files. - [COMMAND_EXECUTION]: The skill executes a local Node.js script located at
plugins/ruflo-cost-tracker/scripts/export.mjsusing the Bash tool to perform the export operations. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill processes
session-*andbudget-config-*records retrieved from thecost-trackingnamespace in AgentDB. - Boundary markers: None are specified to delimit the retrieved database content during processing or transmission.
- Capability inventory: The skill has the ability to perform network POST requests (via webhooks) and local filesystem writes based on instructions contained within its arguments.
- Sanitization: There is no evidence of sanitization or schema validation performed on the database records before they are exported to external systems.
Audit Metadata