T06 · System Persistence
- Location
SKILL.md:43- Finding
Persistent interception proxy for Anthropic API traffic
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a legitimate cost-saving purpose, but it asks users to install and persistently route Anthropic API traffic through a third-party local proxy with limited containment guidance.
Install only if you intentionally want OpenClaw Anthropic traffic, including prompts, tool results, and API headers, to pass through Tamp. Prefer a temporary foreground run first, review the Tamp package and dependencies, avoid sudo, keep direct Anthropic access as the default or fallback, and know how to disable the service and remove the provider configuration before enabling persistence.
SKILL.md:43Persistent interception proxy for Anthropic API traffic
SKILL.md:18Execution of externally retrieved and insufficiently verified dependencies
The skill advertises broad trigger phrases like saving tokens, reducing API costs, and token compression, which can cause the agent to invoke this skill for general budgeting or model-usage questions rather than explicit proxy setup. That increases the chance of unsolicited infrastructure changes, package installation, and traffic rerouting through a local proxy when the user did not clearly request those actions.
Instructing the user to create a systemd unit in ~/.config/systemd/user establishes a persistent execution mechanism. In this context, the persisted process is a local proxy that rewrites and forwards API requests, so unintended long-term deployment could affect confidentiality, troubleshooting, and future agent behavior.
Create ~/.config/systemd/user/tamp.service:
[Unit]
The command enables a user-level systemd service to start automatically in future sessions, creating persistence beyond the immediate task. Persistence is security-relevant because it keeps a request-intercepting proxy running continuously and may outlive the user's awareness or intent.
systemctl --user daemon-reload
systemctl --user enable --now tamp.service
journalctl --user -u tamp -f # live compression logs
No suspicious patterns detected.