vibe-ledger — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited vibe-ledger (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generates a visual cost report from your project's cost history. Reads vibe/cost/history.json. Writes vibe/cost/ledger/index.html. Opens in browser.
No dependencies. No installs. Works on Mac, Linux, and Windows.
Automatically — vibe-cost calls this at the end of every session after writing history.json.
Manually — when the user says:
ledger: — regenerate and openshow cost report / open ledger / generate ledgerhow much have I spent — if history.json existsls vibe/cost/history.json 2>/dev/null && echo "EXISTS" || echo "MISSING"If missing:
"No cost history found yet. Runcost:after your next session to start tracking, thenledger:to generate the report."
Stop here if missing.
python3 ~/.claude/skills/vibe-ledger/scripts/generate.pyThe script:
vibe/cost/history.json from the current project directoryvibe/cost/ledger/index.html — self-contained, no external dependenciesAfter the script runs, tell the user:
"Ledger generated — opening in your browser.
>
[Project name] · [N] sessions · [N] tasks · $[X.XX] total Report: vibe/cost/ledger/index.html>
Run ledger: any time to refresh it with the latest data."Header — project name, total cost, session count, date range, build progress
Stat cards — avg cost per task, avg cost by size (S/M/L), peak session, cache savings
At a glance — plain English summary: what was built, what it cost, whether costs are healthy
Day by day — cost per day with ASCII block bars
Task size breakdown — S/M/L cost totals with percentage of total spend
Session burn table — each session with dot indicators (each dot ≈ cost/7), colour-coded:
Token composition — reading vs writing cost in plain terms ("reading costs $X of your $Y")
Efficiency metrics — tokens per task, read-to-write ratio, code written per dollar
Top 5 most expensive tasks — with size, phase, input and output tokens
Advice cards — plain English explanations of waste patterns detected, with specific fixes
Forecast — remaining cost estimate based on avg task cost × tasks remaining
vibe/cost/
├── history.json ← source data (written by cost:)
└── ledger/
└── index.html ← generated report (open this)index.html is fully self-contained — no internet required to view it. Share it with a client or team member by just sending the file.
Every cost: session automatically regenerates the ledger. Or run ledger: manually any time to refresh from the current history.json.
The report always reflects the complete project history — not just the last session.
"vibe/cost/history.json not found" → You haven't run cost: yet in this project. Run it after your next session.
"history.json is empty" → The file exists but has no sessions. Run cost: at the end of a session to populate it.
"python3: command not found" → Python is not installed. Install from python.org — it's free and takes 2 minutes. On most Macs and Linux machines, python3 is already available.
Report opens but looks wrong → Try opening vibe/cost/ledger/index.html directly in Chrome or Firefox. The VT323 font requires an internet connection to load from Google Fonts. If offline, it falls back to Share Tech Mono or monospace — same layout, different font.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.