tokenwise
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of a plugin from an unverified community GitHub repository (CodeShuX/tokenwise). The lack of verification for this source poses a risk when executing associated code.
- [COMMAND_EXECUTION]: The /tokenwise:install command modifies the agent's core configuration files, settings.json and CLAUDE.md, to implement routing logic. This allows the skill to persistently change how the agent operates.
- [METADATA_POISONING]: There is a clear discrepancy between the author identifier provided by the system (sickn33) and the author listed in the skill metadata (CodeShuX). Additionally, the skill uses a risk: critical tag and references a potentially fabricated Anthropic issue number (#27665) to build false authority.
- [PERSISTENCE_MECHANISMS]: By modifying the CLAUDE.md and settings.json files, the skill ensures its model routing logic and potential code execution persist across all future agent sessions in the project.
Recommendations
- AI detected serious security threats
Audit Metadata