Back to skill

Security audit

Token Usage Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it says: report token usage and costs from local OpenClaw and Codex session data, with some optional local maintenance features users should review.

Install only if you are comfortable with the skill reading local OpenClaw/Codex session logs and creating local aggregate usage data. Treat exported JSON or Telegram-ready reports as sensitive metadata, review the hardcoded IST timezone behavior, and do not let an agent run the documented gzip/move archive commands unless you explicitly want old session files changed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a usage-and-cost tracking/reporting skill for OpenClaw sessions, but the supplied code is a pricing updater utility. Its primary function is to retrieve model pricing from an external API, combine that with hardcoded fallback/direct rates, and generate pricing/registry JSON artifacts. It does not inspect sessions, track token consumption, aggregate usage over time, or report OpenClaw token usage across sessions. The external network fetch and file-generation behavior are also undeclared in the provided permissions/description, making this a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly promotes a cron job that sends token usage reports to Telegram, which transmits potentially sensitive operational metadata off-system. Even though this is documentation rather than executable code, normalizing off-platform reporting without a privacy warning, data-minimization guidance, or redaction advice can lead users to leak usage patterns, model names, schedules, and cost information to third-party services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill documentation describes operations that read many local session files, write logs and JSON exports, run shell commands, and includes archiving commands that modify persistent data, but it does not declare any tool scope or permissions boundaries. In an agent ecosystem, undeclared capabilities increase the chance the skill is invoked with broader authority than users expect, enabling unintended file access or modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance uses broad phrases like asking how many tokens were used today or wanting budget monitoring, which can overlap with ordinary conversation and cause over-eager automatic invocation. In an agent setting, ambiguous triggers can lead to unnecessary access to local session history and generation of reports without clear user intent for filesystem analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown states that '--today' and '--yesterday' use the local system timezone '(Asia/Calcutta / IST by default)', which imposes a specific locale behavior rather than offering user choice. This can violate language/locale policy expectations when users are in other regions or do not want IST-based interpretation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
- Claude Sonnet 4: $3.00/1M input, $15.00/1M output
- GPT-4o: $2.50/1M input, $10.00/1M output

Costs are approximate. Cache read/write pricing applied when available. Unprefixed model names (e.g. `k3`) are automatically mapped to their full form (`kimi/k3`) for pricing lookup.

## Session File Management

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

ls ~/.openclaw/agents/main/sessions/*.jsonl | wc -l

Size by month (to identify heavy periods)

ls -l ~/.openclaw/agents/main/sessions/*.jsonl | awk ' {month = substr($6, 1, 3); year = $8; size += $5; count++} END {printf "Total: %.2f MB across %d files\n", size/1024/1024, count}'

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The skill includes commands to gzip and move old session files into an archive, which alters persistent session data outside pure reporting. In an agent context, exposing destructive or state-changing maintenance actions alongside normal analytics increases the risk of unintended retention changes, loss of easy access, or interference with forensic/history needs.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

find ~/.openclaw/agents/main/sessions/*.jsonl -mtime +30 -exec gzip {} ;

Move very old sessions to archive (after verifying no longer needed)

mkdir -p ~/.openclaw/agents/main/sessions/archive find ~/.openclaw/agents/main/sessions/*.jsonl -mtime +90 -exec mv {} ~/.openclaw/agents/main/sessions/archive/ ;

text

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common.py (reported line 89)May include surrounding context.

python
def _zstd_open(path, mode="rt", encoding="utf-8", errors="replace"):
    """Open a zstd-compressed file for text reading via subprocess."""
    import io
    proc = subprocess.Popen(
        ["zstd", "-dc", str(path)],
        stdout=subprocess.PIPE,
        stderr=subprocess.DEVNULL,

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/parse.py (reported line 277)May include surrounding context.

python
production lock or tripping the protected-state guard.

    Uses the SQLite online-backup API rather than a raw file copy: the live DB
    is under constant write (WAL), and a plain shutil.copyfile can catch a torn
    checkpoint, yielding a copy sqlite3 then refuses to open ("unable to open
    database file"). sqlite3.Connection.backup copies a consistent snapshot even
    while the source is being written.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/parse.py (reported line 449)May include surrounding context.

python
def _zstd_stream(path):
    """Yield decompressed text lines from a zstd-compressed session archive."""
    proc = subprocess.Popen(
        ["zstd", "-d", "-c", "--", path],
        stdout=subprocess.PIPE,
        stderr=subprocess.DEVNULL,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a skill for tracking, aggregating, and reporting token usage and costs across sessions. While reading compressed archives is related to that purpose, invoking an external executable via subprocess.Popen introduces process-execution capability that is not obviously justified by a token-reporting skill when a pure-library implementation would avoid that broader capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file sets LOCAL_TZ_NAME to Asia/Calcutta and uses it for timestamp conversion globally. This imposes a specific locale-related behavior without any visible user opt-in or documented region-specific justification, which matches the language/locale policy concern for all file types.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.