caveman-stats

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security concerns were identified. The skill is designed to provide visibility into token usage statistics by accessing local session data.- [DATA_EXFILTRATION]: The skill documentation indicates it reads Claude Code session logs from the local filesystem to calculate token metrics. Access is limited to the session history for statistical reporting purposes.- [SAFE]: The skill uses a hook mechanism to intercept the /caveman-stats command and inject formatted results. This is a platform-specific feature and does not involve arbitrary command execution or external network calls.- [PROMPT_INJECTION]: The skill processes session logs which contain untrusted data from previous turns. However, it functions as a readout tool for numbers rather than an automated instruction processor. * Ingestion points: JSONL session log files on disk. * Boundary markers: Not specified. * Capability inventory: Local file read (logs) and local file write (statusline badge suffix). * Sanitization: None described in documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:05 AM
Security Audit — agent-trust-hub — caveman-stats