Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill is a local token and cost reporting utility that reads OpenClaw/Codex session logs and does not show exfiltration, persistence, destructive actions, or hidden privilege escalation.
Install only if you are comfortable with a local tool reading your OpenClaw/Codex session logs to summarize token usage. Treat reports as potentially sensitive because session filenames, model names, usage patterns, and cron job labels may reveal workflow details; review or avoid the optional pricing updater if you do not want outbound requests to OpenRouter.
- Claude Sonnet 4: $3.00/1M input, $15.00/1M output - GPT-4o: $2.50/1M input, $10.00/1M output Costs are approximate. Cache read/write pricing applied when available. ## Important: What "Total" Means
65/65 vendors flagged this skill as clean.
No suspicious patterns detected.