model-usage

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the codexbar CLI tool using subprocess.check_output to retrieve cost data. These calls use static, hardcoded arguments for subcommand and format, preventing shell injection vulnerabilities. The use of subprocess.check_output is appropriate here as it interacts with the specific local utility required for the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 01:08 AM
Security Audit — agent-trust-hub — model-usage