Back to skill

Security audit

CostHQ

Security checks for vulnerabilities and agentic risk

Overview

This cost-tracking skill is broadly coherent, but it needs Review because it adds broad workflow monitoring, an API-intercepting cache proxy, and dashboard command controls without enough scoping or data-handling detail.

Install only if you are comfortable with a globally installed npm CLI recording agent activity and repository metadata. Avoid enabling the proxy for secrets, customer data, or regulated prompts until retention, cache purge, and access-control behavior are clear. Prefer a pinned reviewed package version and do not run installation commands with elevated privileges unless needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Global npm Packages Create Supply-Chain Code-Execution Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Log AI usage (after each API call)

bash
# Standard cloud model (cost auto-calculated):
cs log-ai -p anthropic -m claude-sonnet-4 --prompt-tokens 8000 --completion-tokens 2000 --json

# Local model with compute duration (NEW in v3.3.0):
# Use --duration in seconds (120) or string (2m30s). Cost is based on registered $/hr rate.

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
# Local model with compute duration (NEW in v3.3.0):
# Use --duration in seconds (120) or string (2m30s). Cost is based on registered $/hr rate.
cs log-ai -p ollama -m llama3 --tokens 4500 --duration 2m30s --local --json

# With all fields:
cs log-ai -p openai -m gpt-4o --prompt-tokens 5000 --completion-tokens 1500 -c 0.04 --agent "Research Agent" --json

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

cs log-ai -p ollama -m llama3 --tokens 4500 --duration 2m30s --local --json

With all fields:

cs log-ai -p openai -m gpt-4o --prompt-tokens 5000 --completion-tokens 1500 -c 0.04 --agent "Research Agent" --json

text

**Agent Name:** Use `--agent "Agent Name"` to track which agent performed the work.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The semantic caching proxy is described as intercepting API calls but the documentation does not warn that prompt and response content may transit, be cached, or otherwise be handled by the proxy. That omission is dangerous because users may route sensitive LLM traffic through it without understanding the confidentiality, retention, or replay implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises automatic tracking of file changes and git commits but does not foreground a clear warning that local repository activity will be monitored and recorded. This creates a privacy and data-governance risk, especially in sensitive repos where filenames, commit metadata, or change history may themselves be confidential.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
>
> | OS | Install build tools |
> |---|---|
> | **Ubuntu/Debian** | `sudo apt-get install -y build-essential python3` |
> | **macOS** | `xcode-select --install` |
> | **Windows** | `npm install -g windows-build-tools` or install Visual Studio Build Tools |
> | **Alpine** | `apk add build-base python3` |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The repeated 'Always' guidance encourages invocation for nearly every multi-step task and after each API call, causing pervasive monitoring behavior by default. In practice this can normalize broad collection of workflow metadata, token usage, file changes, and git activity without case-by-case user awareness or minimization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documented dashboard capabilities include real-time CLI execution and granular session termination, which are operational control features beyond simple cost and audit tracking. In a skill presented as observability tooling, these controls create a broader attack surface and could enable command execution or disruption if exposed without strong authorization and clear user consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents a semantic caching proxy that intercepts API traffic and can serve cached responses, which expands the skill from passive cost tracking into active handling of prompts and responses. Because no safeguards, scoping limits, or data-handling warnings are provided, users may unknowingly route sensitive model inputs/outputs through a local interception layer that could retain or replay sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.