by Javis603
Local-first desktop widget for tracking token usage, costs, and limits across 36+ AI coding tools—including Claude Code, Codex, Cursor, OpenCode, and OpenClaw—with multi-device sync.
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
# Add to your Claude Code skills
git clone https://github.com/Javis603/token-monitorGuides for using ai agents skills like token-monitor.
Last scanned: 6/17/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@jimp/core: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jimp/custom: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "electron-icon-builder: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "file-type: file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data uses unsafe random function in form-data for choosing boundary",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "icon-gen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jimp: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "phantomjs-prebuilt: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "phin: phin may include sensitive headers in subsequent requests after redirect",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "request: Server-Side Request Forgery in Request",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "svg2png: XSS in svg2png (NPM package)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tar: node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tmp: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tough-cookie: tough-cookie Prototype Pollution vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Memory exhaustion DoS from tiny fragments and data chunks",
"severity": "high"
},
{
"type": "npm-audit",
"message": "yargs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "yargs-parser: yargs-parser Vulnerable to Prototype Pollution",
"severity": "medium"
},
{
"file": "README.md",
"line": 37,
"type": "dangerous-command",
"message": "Dangerous command (writes to Claude config): \"> | Claude Code | `~/.claude/projects/`, `~/.claude/\"",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-06-17T09:02:18.223Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how token-monitor compares with popular alternatives.
A desktop widget that shows live token usage and AI Tool Limits across 36+ AI coding tools — Claude Code, Codex, Cursor, GitHub Copilot, Cherry Studio, and more — with real-time multi-device sync, historical usage trends, and breakdowns by tool, device, model, session, or project.
Token Monitor supports token usage, account-limit checks, and session details separately:
| Logo | Tool | Data path | Token Usage | AI Tool Limits | Session Details |
|---|---|---|---|---|---|
| Claude Code | ~/.claude/projects/, ~/.claude/transcripts/ |
✅ | ✅ | ✅ | |
| Codex | ~/.codex/ (sessions/, archived_sessions/) |
✅ | ✅ | ✅ | |
| OpenCode | ~/.local/share/opencode/ (opencode*.db, storage/message/) |
✅ | ✅ | ✅ | |
| Hermes Agent | ~/.hermes/state.db |
✅ | — | — | |
| OpenClaw | ~/.openclaw/agents/ |
✅ | — | — | |
| Cursor IDE / Cursor CLI | ~/.config/tokscale/cursor-cache/ (account-level usage export) |
✅ | ✅ | — | |
| Antigravity | ~/.gemini/ (antigravity/, antigravity-ide/, antigravity-backup/, antigravity-cli/conversations/) |
✅ | ✅ | — | |
| Cline | VS Code globalStorage tasks (.../saoudrizwan.claude-dev/tasks/), ~/.cline/data/sessions/ |
✅ | — | — | |
| Factory Droid | ~/.factory/sessions/ |
✅ | ✅ | — | |
| Kimi CLI / Kimi Code / Kimi Work | ~/.kimi/sessions/, ~/.kimi-code/sessions/, <platform-app-data>/kimi-desktop/ |
✅ | ✅ | — | |
| Qwen CLI | ~/.qwen/projects/ |
✅ | — | — | |
| Grok Build | ~/.grok/ (sessions/, logs/unified.jsonl) |
✅ | ✅ | — | |
| GitHub Copilot | VS Code workspaceStorage/*/chatSessions/, ~/.copilot/ (otel/, data.db) |
✅ | ✅ | — | |
| Pi / Oh My Pi | ~/.pi/agent/sessions/, ~/.omp/agent/sessions/ |
✅ | — | — | |
| Zed | ~/.local/share/zed/threads/threads.db |
✅ | ✅ | — | |
| Kilo | ~/.local/share/kilo/kilo.db; VS Code globalStorage tasks (.../kilocode.kilo-code/tasks/) — extension logs on Linux & remote/WSL only |
✅ | — | — | |
| Command Code | ~/.commandcode/projects/**/*.jsonl |
✅ | ✅ | — | |
| MiMo Code | ~/.local/share/mimocode/mimocode.db |
✅ | ✅ | — | |
| ZCode / GLM | ~/.zcode/ (projects/, cli/db/db.sqlite) |
✅ | ✅ | — | |
| Kiro | ~/.kiro/sessions/cli/, Kiro IDE globalStorage & kiro-cli DB |
✅ | ✅ | — | |
| CodeBuddy | ~/.codebuddy/projects/ + IDE / VS Code extension logs |
✅ | — | — | |
| WorkBuddy | ~/.workbuddy/projects/, ~/.workbuddy/workbuddy.db |
✅ | ✅ | — | |
| Proma | ~/.proma/agent-sessions/*.jsonl |
✅ | — | — | |
| Qoder | <platform-app-data>/QoderCN/SharedClientCache/cache/db/local.db (CN only) |
✅ | ✅ | — | |
| Reasonix | ~/.reasonix/ (stats/, sessions/, projects/*/sessions/) |
✅ | — | — | |
| DeepSeek / DeepSeek Harness | ~/.dsh/sessions/ (session.jsonl, session.jsonl.zstd) |
✅ | ✅ | ✅ | |
| Cherry Studio | <platform-app-data>/CherryStudio/ (Data/Agents/.claude/projects/ V2, .claude/projects/ legacy) |
✅ | — | — | |
| LM Studio | ~/.lmstudio/server-logs/**/*.log |
✅ | — | — | |
| Unsloth Studio | ~/.unsloth/studio/studio.db |
✅ | — | — | |
| OpenRouter | OpenRouter API key (usage/key limit; balance when credits access is authorized, documented for Management keys) | — | ✅ | — | |
| Minimax | Minimax API key (Token Plan quota via Minimax API) | — | ✅ | — | |
| Volcengine | Ark API key or Volcengine AK/SK (Ark Coding Plan & Agent Plan quota via Volcengine API) | — | ✅ | — | |
| Ollama | Ollama Cloud cookie (session/weekly usage via ollama.com/settings) | — | ✅ | — | |
| Trae CN | Trae CN access token (Trae CN / SOLO credits via trae.cn) | — | ✅ | — | |
| Alibaba Cloud | Alibaba Cloud console cookie (Bailian / Model Studio Token Plan quota, Team & Personal) | — | ✅ | — | |
| Third-party APIs | New API / Sub2API-compatible account presets (including compatible One API forks), a New API API-key preset, and a Custom balance endpoint | — | ✅ | — |
Paths above are the defaults. Token Monitor follows the same environment overrides Tokscale does — $XDG_DATA_HOME for the ~/.local/share/ roots, and per-tool variables such as $CODEX_HOME, $GROK_HOME, $HERMES_HOME, $KIMI_CODE_HOME, $UNSLOTH_STUDIO_HOME, $LM_STUDIO_HOME, $DSH_HOME, $REASONIX_STATE_HOME, $REASONIX_HOME and the $CLINE_* family.
LM Studio tracking currently covers OpenAI-compatible /v1/chat/completions and /v1/responses requests recorded in server logs. Conversations started from LM Studio's built-in Chat UI and native /api/v1/chat requests are not included.
Unsloth Studio tracks inference usage from studio.db: Studio chats and its local API. Local inference has zero API cost; recognized metered providers use Tokscale's price estimates. Training tokens are not included. See Unsloth source notes.
Command Code transcripts do not contain actual token counts or per-message model metadata. Token usage is estimated from transcript text, while model attribution and derived cost may reflect the currently configured model rather than the model historically used for each request.
The Cursor cache comes from Cursor's account-level usage export, so it covers Cursor IDE and Cursor CLI alike. Token Monitor automatically detects accounts signed in through the Cursor desktop app and also supports adding accounts manually in Settings. The cache re-syncs automatically when stale, but
token-monitor is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Javis603. Local-first desktop widget for tracking token usage, costs, and limits across 36+ AI coding tools—including Claude Code, Codex, Cursor, OpenCode, and OpenClaw—with multi-device sync. It has 2,149 GitHub stars.
token-monitor failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/Javis603/token-monitor" and add it to your Claude Code skills directory (see the Installation section above).
token-monitor is primarily written in JavaScript. It is open-source under Javis603 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh token-monitor against similar tools.
No comments yet. Be the first to share your thoughts!
Based on votes and bookmarks from developers who liked this skill