Back to skill

Security audit

TokenLens Token Value Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local token-usage helper with some overstated documentation, but I found no hidden, destructive, network, or privilege-seeking behavior.

Before installing, treat this as a simple local helper rather than a full optimization engine. It stores token usage/config data under ~/.openclaw/workspace/memory/tokenlens/, uses mock or historical estimates, and does not actually apply most recommended OpenClaw changes for you. Only add the suggested cron or heartbeat schedule if you are comfortable with ongoing local history collection.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code does relate to token/context optimization, so the description is not wholly unrelated. However, the declared description overstates the implementation. The script performs a narrow, rule-based prompt analysis to decide which context files to load and provides a rough token-savings estimate. It does not implement cost tracking, premium upgrade behavior, or a broader optimization engine for maximizing token value. Its main behavior is local context-loading recommendation and AGENTS.md snippet generation, which is materially narrower than the declared product description.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SECURITY.md (reported line 17)May include surrounding context.

md
- No telemetry, no tracking, no analytics

2. **No Code Execution**
   - Scripts do not execute arbitrary code
   - No subprocess calls (except OpenClaw CLI for token tracking)
   - No dynamic code evaluation (eval, exec)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
60% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 22)May include surrounding context.

md
- No dynamic code evaluation (eval, exec)

3. **No System Modifications**
   - Scripts do not modify system files
   - All configuration changes are via OpenClaw config API
   - No installation of system packages

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill advertises scripts that read from and write to local files, but it does not declare any explicit tool scope or permissions. This creates a transparency and least-privilege problem: users and hosting platforms cannot accurately assess what file access the skill requires before installation or execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation tells users to run optimization commands, including an --apply flow elsewhere, without warning that these actions may modify local configuration or stored data. In a skill that claims automation and optimization of local OpenClaw behavior, silent config changes can cause unexpected state changes, break workflows, or alter user settings without informed consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/model_router.py (reported line 138)May include surrounding context.

python
return tier, confidence, details

def get_current_model() -> str:
    """Try to detect current model (simplistic)."""
    # This would need to read OpenClaw config
    # For now, return a placeholder
    return "unknown"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring says "Apply optimizations (if apply=True)" and the output says "Applying:" plus "Optimizations applied," which implies real changes are made. In reality, the code only prints commands and writes last_optimization_date to config, while comments at L283-L284 acknowledge nothing is actually executed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The setup guidance recommends recurring automated checks via heartbeat or cron without adequately warning that this may result in continued local data collection and storage over time. Even if data remains local, persistent background collection can surprise users, accumulate sensitive usage history, and increase privacy risk on shared or unmanaged systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code prints all user-facing messages in English only, including recommendations and instructions. Under the policy for natural-language violations, forcing a specific language without user opt-in is a locale/language constraint that should be surfaced.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.