model-usage
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/model_usage.pyscript executes thecodexbarCLI tool using a list of arguments viasubprocess.check_output. This implementation avoids shell interpolation and is a secure method for invoking external processes. The CLI inputs are constrained by the script's argument parser to a fixed set of providers. - [COMMAND_EXECUTION]: Documentation in
references/codexbar-cli.mdspecifies that thecodexbartool reads local usage logs from the user's home directory (e.g.,~/.codexand~/.claude). This access is necessary for the skill's primary function of summarizing local AI usage costs. - [EXTERNAL_DOWNLOADS]: The
SKILL.mdmetadata provides installation instructions for thecodexbarCLI via a third-party Homebrew tap. This is a standard method for managing development dependencies and follows expected patterns for CLI-based AI agent skills.
Audit Metadata