by Javis603
Real-time token, cost, and AI limits widget with multi-device sync for Claude Code, Codex, OpenCode, Hermes, OpenClaw, Cursor, Antigravity and more. | 为 AI Tools 打造的即时Token、成本与限额监控桌面组件,支持多设备同步
# Add to your Claude Code skills
git clone https://github.com/Javis603/token-monitorGuides for using ai agents skills like token-monitor.
Last scanned: 6/17/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@jimp/core: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jimp/custom: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "electron-icon-builder: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "file-type: file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data uses unsafe random function in form-data for choosing boundary",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "icon-gen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jimp: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "phantomjs-prebuilt: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "phin: phin may include sensitive headers in subsequent requests after redirect",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "request: Server-Side Request Forgery in Request",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "svg2png: XSS in svg2png (NPM package)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tar: node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tmp: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tough-cookie: tough-cookie Prototype Pollution vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Memory exhaustion DoS from tiny fragments and data chunks",
"severity": "high"
},
{
"type": "npm-audit",
"message": "yargs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "yargs-parser: yargs-parser Vulnerable to Prototype Pollution",
"severity": "medium"
},
{
"file": "README.md",
"line": 37,
"type": "dangerous-command",
"message": "Dangerous command (writes to Claude config): \"> | Claude Code | `~/.claude/projects/`, `~/.claude/\"",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-06-17T09:02:18.223Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}token-monitor is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Javis603. Real-time token, cost, and AI limits widget with multi-device sync for Claude Code, Codex, OpenCode, Hermes, OpenClaw, Cursor, Antigravity and more. | 为 AI Tools 打造的即时Token、成本与限额监控桌面组件,支持多设备同步. It has 886 GitHub stars.
token-monitor failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/Javis603/token-monitor" and add it to your Claude Code skills directory (see the Installation section above).
token-monitor is primarily written in JavaScript. It is open-source under Javis603 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh token-monitor against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
A desktop widget that shows live token usage and AI Tool Limits across various AI coding tools (Claude Code, Codex, Hermes Agent, OpenCode, OpenClaw, Cursor, Antigravity, Cline, and more) with real-time multi-device sync, historical usage trends, and breakdowns by tool, device, model, or session.
Token Monitor supports token usage, account-limit checks, and session details separately:
| Logo | Tool | Data path | Token Usage | AI Tool Limits | Session Details |
|---|---|---|---|---|---|
| Claude Code | ~/.claude/projects/, ~/.claude/transcripts/ |
✅ | ✅ | ✅ | |
| Codex | ~/.codex/sessions/ |
✅ | ✅ | ✅ | |
| OpenCode | ~/.local/share/opencode/ |
✅ | ✅ | ✅ | |
| Hermes Agent | $HERMES_HOME/state.db or ~/.hermes/state.db |
✅ | — | — | |
| OpenClaw | ~/.openclaw/agents/ |
✅ | — | — | |
| Cursor | ~/.config/tokscale/cursor-cache/ (kept fresh by Cursor sync) |
✅ | ✅ | — | |
| Antigravity | ~/.config/tokscale/antigravity-cache/ (kept fresh by Antigravity sync) |
✅ | ✅ | — | |
| Cline | VS Code globalStorage tasks (.../saoudrizwan.claude-dev/tasks/) |
✅ | — | — | |
| Kimi CLI / Kimi Code | ~/.kimi/sessions/, ~/.kimi-code/sessions/ (KIMI_CODE_HOME); Kimi Code API key (Kimi Code quota via Kimi API) |
✅ | ✅ | — | |
| Qwen CLI | ~/.qwen/projects/ |
✅ | — | — | |
| Grok Build | $GROK_HOME/sessions/ or ~/.grok/sessions/ |
✅ | ✅ | — | |
| GitHub Copilot | VS Code workspaceStorage/*/chatSessions/, ~/.copilot/otel/ |
✅ | ✅ | — | |
| Pi | ~/.pi/agent/sessions/, ~/.omp/agent/sessions/ (Oh My Pi) |
✅ | — | — | |
| Zed | ~/.local/share/zed/threads/threads.db |
✅ | — | — | |
| Kilo Code | VS Code globalStorage tasks (.../kilocode.kilo-code/tasks/) — Linux & remote/WSL only |
✅ | — | — | |
| MiMo Code | ~/.local/share/mimocode/mimocode.db |
✅ | ✅ | — | |
| ZCode / GLM | ~/.zcode/projects/; Z.ai API key (GLM personal/team Coding Plan quota via Z.ai API) |
✅ | ✅ | — | |
| Kiro | ~/.kiro/sessions/cli/, Kiro IDE globalStorage & kiro-cli DB |
✅ | ✅ | — | |
| CodeBuddy | ~/.codebuddy/projects/ + IDE / VS Code extension logs |
✅ | — | — | |
| WorkBuddy | ~/.workbuddy/projects/, ~/.workbuddy/workbuddy.db |
✅ | — | — | |
| Proma | ~/.proma/agent-sessions/*.jsonl |
✅ | — | — | |
| DeepSeek | DeepSeek API key (balance via DeepSeek API) | — | ✅ | — | |
| Minimax | Minimax API key (Token Plan quota via Minimax API) | — | ✅ | — | |
| Volcengine | Ark API key or Volcengine AK/SK (Ark Coding Plan quota via Volcengine API) | — | ✅ | — | |
| Qoder | Qoder dashboard cookie (big-model credits via Qoder usage API) | — | ✅ | — | |
| Ollama | Ollama Cloud cookie (session/weekly usage via ollama.com/settings) | — | ✅ | — |
| Home View | Limits View | Tools View |
|---|---|---|
![]() |
![]() |
![]() |
| Session View | Models View | Service Status |
|---|---|---|
![]() |
![]() |
![]() |
| Usage Dashboard — Overview | Usage Dashboard — Trends |
|---|---|
![]() |
![]() |
Most usage monitors are useful on the machine they run on. Token Monitor is built for multi-device work: each device watches its own local logs, sends summary updates to your hub, and every connected widget sees token changes almost immediately.