Back to skill

Security audit

Claude API Cost Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only cost optimization skill with disclosed local caching and logging risks, but no hidden execution or deceptive behavior.

Before installing or copying the examples, avoid caching secrets, credentials, PII, or regulated content; keep cache/log files out of source control; set short retention; and enforce restrictive permissions, especially 0700 on cache directories and 0600 on files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/implementation.md:258
Finding

Local Cache Stores Potentially Sensitive Data Without Enforced Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: references/implementation.md, lines 258–259 and 301–302
Vulnerability Type: Insecure local storage and filesystem permissions
Risk Level: Medium

Vulnerable code:

python
CACHE_DIR = Path.home() / ".claude_cache"
CACHE_DIR.mkdir(exist_ok=True)
python
with open(cache_file, "w") as f:
    json.dump(result, f)

Technical Analysis

The implementation creates a cache directory and writes API responses without explicitly enforcing restrictive permissions. The resulting permissions depend on the process umask. Under common defaults, the directory may be created as 0755 and files as 0644, potentially permitting other local users to traverse the directory and read cached content.

This is security-sensitive because the Skill explicitly warns that its cache can contain source code, prompts, API responses, credentials, personally identifiable information, or other confidential material. Although the documentation advises users to run chmod 600 ~/.claude_cache/, the implementation does not enforce that protection.

Moreover, mode 0600 is inappropriate for a directory because directories require the execute bit for traversal. The correct baseline is 0700 for the cache directory and 0600 for cache files.

Attack Path

  1. A user adopts the documented local-caching implementation on a shared or multi-user system.
  2. The process creates ~/.claude_cache using permissions derived from a permissive umask.
  3. Claude API responses influenced by confidential prompts or source code are written to cache files without an explicit 0600 mode.
  4. Another local account enumerates or directly accesses the cache directory.
  5. The local attacker reads cached responses and recovers confidential information contained in them.

Exploitation requires local filesystem access through another account or process and permissions that allow traversal or reading; t ...[truncated 482 chars]

Remediation
View remediation

Remediation Suggestions

Enforce secure permissions in code rather than relying on documentation or the caller's umask:

python
CACHE_DIR.mkdir(mode=0o700, exist_ok=True)
os.chmod(CACHE_DIR, 0o700)

fd = os.open(
    cache_file,
    os.O_WRONLY | os.O_CREAT | os.O_TRUNC,
    0o600,
)
with os.fdopen(fd, "w") as f:
    json.dump(result, f)

Additional hardening measures:

  • Use 0700 for cache directories and 0600 for files.
  • Correct the documentation so it does not recommend chmod 600 for a directory.
  • Reject symbolic links and verify that the cache path remains under the expected directory.
  • Write through a securely created temporary file and atomically rename it to avoid partial files and race conditions.
  • Apply restrictive permissions to existing directories and files, not only newly created ones.
  • Do not cache credentials, secrets, personal data, or regulated information.
  • Use a short retention period and securely remove expired cache entries.
  • Prefer encrypted or ephemeral storage in shared, CI, and hosted environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
# Claude API Cost Optimizer

> ⚠️ **Local Data Warning:** This skill creates `~/.claude_cache/`, `costs.log`, and `batch_results.jsonl` which may contain source code, API responses, and prompts. Set `chmod 600` on these files, never cache secrets/PII, and add cache directories to `.gitignore`.

Cut Claude API costs by 70–90% using intelligent model selection, caching, and batching.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
# Claude API Cost Optimizer

> ⚠️ **Local Data Warning:** This skill creates `~/.claude_cache/`, `costs.log`, and `batch_results.jsonl` which may contain source code, API responses, and prompts. Set `chmod 600` on these files, never cache secrets/PII, and add cache directories to `.gitignore`.

Cut Claude API costs by 70–90% using intelligent model selection, caching, and batching.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/implementation.md (reported line 5)May include surrounding context.

md
# Implementation Patterns

> **Security note — local caching:** Patterns in this file cache API responses and codebases to local files (e.g. `~/.claude_cache/`, `costs.log`, `batch_results.jsonl`). These files may contain source code, API responses, or other sensitive data.
> - Set file permissions: `chmod 600 ~/.claude_cache/` and any log files
> - Never cache content containing secrets, credentials, or PII
> - Set a short `max_age_hours` TTL and clear cache regularly
> - Add cache directories to `.gitignore`

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains executable example code that creates ~/.claude_cache and writes API response text to JSON files. Although the file has a general security note earlier, this specific example performs local persistence of potentially sensitive response content without an inline warning, comment, or disclosure near the operation itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The example code writes usage and cost data to costs.log, which is a file write affecting local user data. The document includes a top-level security note about local caching and logs, but this section lacks a section-specific warning or comment by the file append operation itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cost-tracking template encourages logging detailed request metadata but does not warn that prompts, task labels, token patterns, timestamps, and related telemetry can expose sensitive business data or facilitate correlation with secrets-bearing workflows. In this skill’s context, local caching and cost logging are explicitly enabled, which increases the chance that users will persist operationally sensitive API usage data without applying redaction, access controls, or retention limits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.