Back to skill

Security audit

Openclaw Cost Optimization

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language cost-optimization guide with manual configuration examples and no hidden code or automatic execution.

Before installing, note that the guide is written in Chinese and includes commands/config snippets that can change which model OpenClaw uses. Only apply those changes intentionally, and verify current provider pricing and billing implications before switching models.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

bash
# 临时切换
openclaw ask "问题" --model claude-sonnet

# 永久切换
openclaw config set model deepseek-chat

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title, description, and all user-facing guidance are presented only in Chinese, which imposes a specific language on users without any opt-in or alternative locale. The file does not indicate that the skill is intentionally region-specific or provide a language selection mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description is written in Chinese, which implies a fixed language presentation for the skill metadata without any indication that users can choose another language. Under the stated policy, language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.