Back to skill

Security audit

Token Budget

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only token budget helper that stays aligned with local usage tracking, with a caveat that it can activate on broad cost or token questions.

Reasonable to install if you want local token and spend summaries. Be aware it may activate when you ask general questions about API costs or token usage, and it may keep local threshold/history data in the disclosed OpenAuthority budget state file. Use stronger platform or provider-side controls for hard spending limits.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is configured to activate on broad natural-language topics such as budget, spend tracking, token usage, and API costs, which can cause unintended invocation during ordinary conversation. That increases prompt-surface area and may trigger file/state access or behavior changes when the user did not explicitly request the skill, creating opportunities for confusion, undesired disclosure of local usage data, or interaction with other instructions in unsafe ways.

Static analysis

No suspicious patterns detected.