Back to skill

Security audit

token-stats-reporter

Security checks for vulnerabilities and agentic risk

Overview

This skill reads local OpenClaw session logs to calculate token and cost summaries, which matches its stated purpose and shows no exfiltration, persistence, or destructive behavior.

Install only if you are comfortable with the skill reading your local OpenClaw session logs to compute token totals. It does not appear to send data anywhere or modify files, but users should be aware that broad trigger phrases may invoke local history scanning unless the agent asks for confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and generic (e.g., token统计, 费用多少, 省了多少钱), which can cause the skill to activate in contexts where the user did not explicitly consent to local session analysis. Because the skill’s documented behavior includes scanning local session files, overbroad activation increases the chance of unintended disclosure of usage history and metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation states that all data is read from ~/.openclaw/agents/main/sessions/*.jsonl, but this local filesystem access is not prominently disclosed in the top-level description or trigger metadata. Users may invoke the skill thinking it performs a harmless calculation, when it actually inspects local session history, creating a transparency and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Reading session transcripts from a local history directory without prominent disclosure is a privacy/security issue because users may not expect the skill to inspect stored conversations to produce its output. Even though the script appears to use usage metadata, it still opens and parses transcript files, which can contain sensitive content from prior sessions and broadens data exposure unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring, argparse descriptions, and printed output are written in Chinese only, which imposes a specific language on users without opt-in or an alternative locale. This matches the language/locale policy concern for natural-language behavior because the skill does not offer any language selection or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script scans all JSONL session logs under ~/.openclaw/agents/main/sessions, which means it accesses historical local conversation data rather than only processing explicit input passed to the tool. In a token-reporting skill, this broad transcript access creates a privacy risk because sensitive prompts, model metadata, and usage records from unrelated sessions may be processed without clear user consent or scope limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes support for two reference rate schemes: Anthropic Claude Opus 4.7 and OpenAI GPT-5.5, with Opus 4.7 as default. However, the script also exposes a --rates option that accepts any three custom pricing values, expanding behavior beyond the stated two-model scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.