Back to skill

Security audit

Token Saver Skill

Security checks for vulnerabilities and agentic risk

Overview

TokenSaver appears purpose-built for reducing token usage, but it automatically processes full conversation history through an unverifiable dependency and has unclear cache retention and installation provenance.

Review this skill before installing in sensitive workspaces. It is aligned with token saving, but it may transform and cache conversation content, and the core optimizer is not present or pinned in the artifact. Prefer a pinned installer and a reviewed, locked @token-saver/core version, and avoid using it with secrets or confidential conversations unless cache scope, retention, and clearing behavior are acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:23
Finding

Mutable npm Release Executed During Installation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
apps/openclaw-integration/dist/index.js:3
Finding

Unpinned External Core Dependency Receives Complete Conversation Context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to execute npx clawhub@latest install tokensaver, which pulls and runs the latest published package version without pinning to a known-good release. If the package is compromised, unpublished/replaced in a supply-chain incident, or a breaking/malicious version is released, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The semantic cache feature explicitly reuses responses to similar queries, but the skill does not clearly warn users that prior query content may be retained, compared, and surfaced later. This creates confidentiality and privacy risk, especially if prompts contain secrets, proprietary material, or sensitive user context that could be reused across later interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill maps broad natural-language phrases directly to command execution, which can cause unintended activation during ordinary conversation rather than explicit user intent. In an agent environment, ambiguous triggers can silently change optimization modes or disable protections, creating a prompt/command confusion risk even without malicious code execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Phrases such as 'Use balanced mode' or 'Default settings' are generic enough to appear in normal discussion, making accidental command invocation likely. Because these triggers alter runtime behavior, an attacker could also embed them in conversational content to influence the skill indirectly through prompt injection-style phrasing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The plugin automatically rewrites conversation context before each AI request by calling the optimizer on the full conversation without obtaining explicit per-request consent or clearly surfacing that content may be compressed, summarized, or altered. In an AI-assistant context, silent transformation of prompts can change meaning, omit critical safety or user instructions, and produce integrity and privacy risks if users believe the original context is being sent unchanged.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Analytics/status triggers are less dangerous than mode-changing commands, but broad phrases like 'Token status' or 'How much am I saving?' can still collide with ordinary speech and cause unintended disclosure of session metadata. In shared or sensitive contexts, even token usage and cache statistics may expose operational details the user did not mean to request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The detailed report text states 'TokenSaver auto-suggests new chat when topics change', which is an affirmative capability claim in the skill's inline documentation/output. In this file, the implemented behavior is limited to context optimization, cache/stat reporting, mode changes, and notifications; there is no code that detects topic changes or suggests a new chat.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.