Back to skill

Security audit

LLM Cost Guard

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local cost ledger, but it overpromises budget blocking and alerts while also documenting scheduled/external reporting in a way users could misunderstand.

Treat this as a manual local spend tracker, not as a guardrail that will stop LLM calls or enforce user quotas. Before installing, verify any cron entry yourself, avoid logging sensitive user identifiers, and do not rely on the documented WhatsApp/Telegram/Discord alerts unless the implementation is fixed and clearly configured.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
main.js:326
Finding

Advertised Budget Enforcement and Alerting Controls Are Not Implemented

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
main.js:215
Finding

Unvalidated Numeric Arguments Permit Cost-Ledger and Limit Manipulation

Content
View full analysis
'); } } ``` ### Technical Analysis Token counts and monetary limits are parsed but never validated. The code accepts: - Negative token counts. - Negative or zero limits. - Partially numeric strings accepted by `par ...[truncated 2170 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
main.js:68
Finding

Non-Atomic Read-Modify-Write Storage Can Lose Concurrent Usage Records

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

bash
# Log an LLM call
llm-cost-guard log --model gpt-4o --input-tokens 1500 --output-tokens 800 --user alice

# Check current spend
llm-cost-guard status

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

bash
# Log an LLM call
llm-cost-guard log --model gpt-4o --input-tokens 1500 --output-tokens 800 --user alice

# Check current spend
llm-cost-guard status

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · main.js (reported line 319)May include surrounding context.

js
Examples:
  llm-cost-guard status
  llm-cost-guard log --model gpt-4o --input 1500 --output 800 --user alice
  llm-cost-guard report month
  llm-cost-guard set-limit daily 5.00
  llm-cost-guard reset today

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README makes privacy/security assurances that conflict with other documented behavior: it advertises report delivery via WhatsApp/Telegram/Discord, which necessarily involves external communications. Misleading claims about 'No external services' and 'No telemetry' can cause users to install or configure the skill under false assumptions about data egress and trust boundaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states that all data is stored locally and that there are no external services, yet it also says the skill auto-installs a cron job that sends summaries and alerts externally. This is a security-relevant contradiction because users may not expect persistent scheduled tasks or outbound transmissions after installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically installing a cron job modifies the host's scheduled tasks and creates persistent behavior without a clearly stated consent step. Persistence plus automatic external reporting increases the risk of unintended data exposure, operational surprises, and difficulty removing the behavior if users are unaware it was added.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that it auto-installs a daily cron job to send reports, alert on budget overages, and reset counters, but does not clearly warn that it will modify scheduled tasks or may send spend data to external messaging channels. Silent persistence and automatic outbound reporting are security-relevant behaviors because they change system state and can leak operational metadata without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation makes a strong privacy/networking claim ('No external services. No telemetry.') while elsewhere advertising outbound alerts via WhatsApp, Telegram, and Discord and scheduled report delivery. This mismatch can mislead users into enabling a skill under false assumptions about data egress and operational behavior, increasing the risk of unintended disclosure of spend, user, or model-usage metadata.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The help text at L312 says set-limit user <key> <USD>, implying limits are tracked per individual user key. However, the implementation at L247-L248 does not read or store the provided user key at all; it only writes one scalar perUserDailyCostLimit, so the documented behavior contradicts the actual code semantics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code removes stored entries for either today's data or all historical data and immediately writes the change to disk. Although this command's purpose includes resetting counters, there is no confirmation prompt or stronger user-facing warning before the destructive operation occurs.

Content

No source excerpt is available for this finding.