cost-track
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local script located at
plugins/ruflo-cost-tracker/scripts/track.mjs. This script is responsible for discovering and parsing Claude Code session logs in the user's home directory to tally token usage. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external files (Claude Code session logs in
.jsonlformat) that may contain untrusted or adversarial content intended to influence the agent's behavior. - Ingestion points: Reading logs from
~/.claude/projects/<encoded-cwd>/<session>.jsonl. - Boundary markers: Absent; the skill documentation does not mention the use of delimiters or specific instructions to ignore embedded commands within the logs.
- Capability inventory: Access to the
Bashtool for script execution and themcp__plugin_ruflo-core_ruflo__memory_storetool for writing results to a database namespace. - Sanitization: Not specified; there is no mention of sanitizing or validating the contents of the logs before they are processed by the tracking script.
Audit Metadata