-
Notifications
You must be signed in to change notification settings - Fork 2
Closed
Labels
P1Priority 1: Critical, fix as soon as possiblePriority 1: Critical, fix as soon as possiblecost-managementCost tracking and optimizationCost tracking and optimizationsecuritySecurity vulnerability or hardeningSecurity vulnerability or hardening
Description
Type: Security / Cost Management
Priority: P1 (Medium severity - prevents surprise bills)
Effort: 2 hours
Phase: 3
Description:
Communities could set expensive models without BYOK, causing unexpected platform costs (e.g., Claude Opus 4 at $15/1M tokens on platform key).
Financial Impact: MEDIUM - Prevents surprise billing
Acceptance Criteria:
- Query OpenRouter API for model costs (or maintain hardcoded table)
- During config validation, warn if expensive model (>$5/1M tokens) without BYOK
- Require BYOK for ultra-expensive models (>$15/1M tokens) - hard error
- Clear error messages explaining cost concerns
- Include cost information in validation output
- Tests for various cost scenarios
Implementation: Add validation in CLI and config loading
Related Issues: Part of security hardening with #64, #65, #66, #68
Branch: feature/issue-64-68-security-hardening
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
P1Priority 1: Critical, fix as soon as possiblePriority 1: Critical, fix as soon as possiblecost-managementCost tracking and optimizationCost tracking and optimizationsecuritySecurity vulnerability or hardeningSecurity vulnerability or hardening