honey-eco
>-
Install this skill
or
25/100
Security score
The honey-eco skill was audited on Aug 2, 2026 and we found 3 security issues across 1 threat category, including 3 critical. Review the findings below before installing.
Categories Tested
Security Issues
critical line 4
Instruction to display credentials
SourceSKILL.md
| 2 | name: honey-eco |
| 3 | description: >- |
| 4 | Report this session's output tokens and CO₂ by running the repo's committed |
| 5 | EcoLogits port, plus the modelled CO₂/$ saved vs a no-Honey baseline — always |
| 6 | labelled with the bench stamp it came from. Use when asked how much Honey saved, |
critical line 25
Instruction to display credentials
SourceSKILL.md
| 23 | ``` |
| 24 | |
| 25 | Then report terse — output tokens, CO₂eq (g), and the `saved` line — in a line or two. Keep the exact numbers the script prints; don't round away precision. |
| 26 | |
| 27 | ## Two numbers, two epistemic statuses — never merge them |
critical line 29
Instruction to display credentials
SourceSKILL.md
| 27 | ## Two numbers, two epistemic statuses — never merge them |
| 28 | |
| 29 | - **CO₂eq is measured** for this session: real output tokens through the EcoLogits port. |
| 30 | - **`saved` is not.** It is a *modelled counterfactual* — how many tokens a no-Honey run |
| 31 | would have emitted — taken from a committed bench stamp. Always pass through the |
Scanned on Aug 2, 2026
View Security Dashboard