tokenwise

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of a plugin from an unverified community GitHub repository (CodeShuX/tokenwise). The lack of verification for this source poses a risk when executing associated code.
  • [COMMAND_EXECUTION]: The /tokenwise:install command modifies the agent's core configuration files, settings.json and CLAUDE.md, to implement routing logic. This allows the skill to persistently change how the agent operates.
  • [METADATA_POISONING]: There is a clear discrepancy between the author identifier provided by the system (sickn33) and the author listed in the skill metadata (CodeShuX). Additionally, the skill uses a risk: critical tag and references a potentially fabricated Anthropic issue number (#27665) to build false authority.
  • [PERSISTENCE_MECHANISMS]: By modifying the CLAUDE.md and settings.json files, the skill ensures its model routing logic and potential code execution persist across all future agent sessions in the project.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 01:30 PM
Security Audit — agent-trust-hub — tokenwise