Back to skill

Security audit

Token Watch

Security checks for vulnerabilities and agentic risk

Overview

TokenWatch is a local-only cost tracking skill whose file writes and usage logging are disclosed and aligned with its purpose.

Before installing, understand that recorded usage history is kept locally in .tokenwatch and exported reports may include model names, token counts, costs, timestamps, task labels, and session IDs. Use generic task labels for sensitive work and delete or relocate the storage directory if you do not want that local history retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill persistently writes detailed usage metadata to local disk by default, including timestamps, model names, task labels, session IDs, alerts, and exported reports, without any consent prompt, warning, retention control, or permission hardening. In an agent environment, task labels and session metadata can reveal sensitive user activity or project context, and local files may be readable by other local users, backup systems, or later processes.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest provides a broad capability description but does not specify any concrete trigger phrases, invocation boundaries, or exclusion conditions. In manifest files, that lack of specificity can make it unclear when the skill should activate versus when general discussion about token costs should not invoke it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest states that data stays on the user's machine in a .tokenwatch directory, and the capabilities include exporting a full usage report to JSON, but there is no warning that usage data will be persisted locally. For markdown/description-style disclosures, behaviors affecting user data should be clearly called out so users understand retention and export implications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The suggestion message at L370 says Gemini 2.5 Flash costs $0.075/1M input tokens, but the pricing table at L056 defines gemini-2.5-flash input cost as 0.30. This is an active contradiction in inline intent/documentation because the user-facing recommendation states a lower price than the code's own pricing data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.