Back to skill

Security audit

Anthropic Token Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is a plain guidance-only skill for reducing Anthropic token costs, with no bundled code or hidden execution behavior.

Safe to install as an instruction-only optimization guide. Before following its recommendations, review any changes to openclaw.json, avoid storing secrets in memory or map files, and inspect the separate atris package before running the optional npx install command.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.