No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by headroomlabs-ai · Agent Tool · ★ 76
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is tokview safe to install? View the security audit →
tokview Wrap your coding agent and watch where every token goes — live, in your terminal, down to the individual tool call. A Codex or Claude Code session burns through millions of tokens, and all you get back is a bill — or, on a subscription, nothing at all. tokview is a tiny local proxy that sits in front of your agent and shows you, as it runs, exactly where the tokens go: by session, by request, by model, and — uniquely — by tool call. No account, no cloud, no code changes. Try it in 30 seconds That's the whole workflow — your agent, the tokens. Agent flags pass stra
| Stars | 76 |
| Forks | 14 |
| Language | Python |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 66.3761883264577/100 |
| Open Issues | 2 |
| Last Updated | 2026-09-30 |
| Created | 2026-05-28 |
| Platforms | claude-code, gemini, python |
| Est. Tokens | ~15k |
These tools work well together with tokview for enhanced workflows:
Explore other popular agent tool tools:
tokview is See where your LLM tokens actually go — down to the individual tool call. A small, local, zero-config proxy + dashboard for token/cost tracking across Claude, OpenAI, Gemini.. It is categorized as a Agent Tool with 76 GitHub stars.
tokview is primarily written in Python.
You can find installation instructions and usage details in the tokview GitHub repository at github.com/headroomlabs-ai/tokview. The project has 76 stars and 14 forks, indicating an active community.
tokview is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: