Back to skill

Security audit

Claude Code API Optimizer Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cost-saving guide, but it asks agents to persist user and project memories and use secondary models without enough consent, privacy, or source-trust controls.

Install only if you are comfortable with persistent memory files. Require review and approval of proposed memories, block secrets and sensitive personal data, restrict writes to a dedicated memory directory, choose any secondary model/provider explicitly, and treat stored memories as user-editable notes rather than trusted instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:66
Finding

Untrusted Conversation Content Can Be Persisted as Long-Term Agent Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
1. **Copy this skill** into your agent's skill directory (or paste `SKILL.md` into your system prompt).

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
version: 1.0.0
author: OpenClaw Community
tags: [optimization, tokens, cost-reduction, context-management, memory]
model: any
---

# Token Optimizer

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs agents to extract and persist user-related information such as preferences, expertise, and project context into memory files, but it provides no privacy guardrails, consent requirements, retention limits, or restrictions on sensitive data. In practice this can lead to unnecessary storage of personal or behavioral data across sessions, increasing privacy, compliance, and data leakage risk if memory files are exposed or reused inappropriately.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.