model-usage

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/model_usage.py script executes the codexbar CLI tool using a list of arguments via subprocess.check_output. This implementation avoids shell interpolation and is a secure method for invoking external processes. The CLI inputs are constrained by the script's argument parser to a fixed set of providers.
  • [COMMAND_EXECUTION]: Documentation in references/codexbar-cli.md specifies that the codexbar tool reads local usage logs from the user's home directory (e.g., ~/.codex and ~/.claude). This access is necessary for the skill's primary function of summarizing local AI usage costs.
  • [EXTERNAL_DOWNLOADS]: The SKILL.md metadata provides installation instructions for the codexbar CLI via a third-party Homebrew tap. This is a standard method for managing development dependencies and follows expected patterns for CLI-based AI agent skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 08:45 AM