Back to skill

Security audit

Skill Cost

Security checks for vulnerabilities and agentic risk

Overview

This skill locally analyzes OpenClaw session logs to report per-skill token usage and cost, with no evidence of network transfer, persistence, credential use, or destructive behavior.

Install only if you are comfortable with a local tool reading OpenClaw session logs under ~/.openclaw/agents and printing aggregate usage, model, day, token, and cost data. Treat exported JSON or screenshots as potentially sensitive because they can reveal your workflow patterns and installed skill usage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The implementation is clearly related to skill-level cost analysis, so the domain is aligned. It parses session data, attributes token/cost shares to a specified skill, and outputs detailed summaries or a side-by-side comparison. However, there are two material mismatches. First, the declaration explicitly says this is a bash-tool skill that must use bash/shell, while the provided code chunk is a Python CLI. Second, the declared purpose and triggers suggest broader capabilities like answering 'which skill costs the most' or providing a general per-skill cost breakdown, but this code does not enumerate all skills or rank them globally; it only handles a single named skill or compares two named skills. That makes the description somewhat broader than the actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly states that the skill scans local OpenClaw session logs, which can contain prompts, tool invocations, file paths, agent names, and cost metadata that may be privacy-sensitive. Omitting a warning or consent guidance can lead users to run the skill without understanding that it processes potentially sensitive local telemetry, increasing the risk of unintended disclosure in terminals, screenshots, shared reports, or JSON exports.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code outputs detailed per-skill, per-model, per-day usage information in JSON, which is derived from session files and may reveal operational patterns or other sensitive metadata. While the file has docstrings, they describe functionality but do not clearly warn users that session data will be read and emitted to stdout/exported.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.