Skip to main content

ecc-tools-cost-audit

Facilitates an evidence-first audit workflow for ECC Tools, addressing cost issues and PR management in GitHub repositories.

Install this skill

or
75/100

Security score

The ecc-tools-cost-audit skill was audited on May 18, 2026 and we found 5 security issues across 1 threat category. Review the findings below before installing.

Categories Tested

Security Issues

medium line 17

Webhook reference - potential data exfiltration

SourceSKILL.md
17- `autonomous-loops` for bounded multi-step audits that cross webhooks, queues, billing, and retries
medium line 28

Webhook reference - potential data exfiltration

SourceSKILL.md
28- the task is in the sibling `ECC-Tools` repo and depends on webhook handlers, queue workers, usage reservation, PR creation logic, or paid-gate enforcement
medium line 49

Webhook reference - potential data exfiltration

SourceSKILL.md
49- webhook router
medium line 138

Webhook reference - potential data exfiltration

SourceSKILL.md
138### 4. App-generated branches re-enter the webhook
medium line 148

Webhook reference - potential data exfiltration

SourceSKILL.md
148- do not begin with broad repo wandering; settle webhook -> queue -> worker first
Scanned on May 18, 2026
View Security Dashboard
Installation guide →