Token Report

PassAudited by ClawScan on May 1, 2026.

Overview

This instruction-only skill matches its stated purpose, but it will post a token-usage screenshot to a hard-coded Feishu chat when invoked.

Before installing or invoking, confirm the Feishu chat ID belongs to the intended group and that token/context usage values are safe to share. If accuracy or confidentiality matters, ask the agent to preview the dashboard before sending.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

When invoked, the agent may send the report screenshot to a Feishu group without an additional confirmation step described in the skill.

Why it was flagged

The skill chains presentation, screenshot, and message-sending tools. This is expected for the stated purpose, but users should notice that invoking the skill can directly send a generated screenshot.

Skill content
用 `canvas action=present` 推送 HTML 仪表盘 ... 用 `browser action=screenshot` 截取 Canvas 画面 ... 用 `message action=send` 发送到目标群
Recommendation

Verify the report content and destination before invoking, or add a confirmation step if accidental posting would matter.

What this means

Members of the configured Feishu chat may see token and context usage information.

Why it was flagged

The artifact says token/context usage metrics for named sessions or agents will be sent to a specific Feishu chat, crossing a team-chat data boundary.

Skill content
内容包含:主会话、Selina、Tars 的 tokens 和 context 用量 ... channel=feishu, target=chat:oc_ee1a93ad1eb6d46a8922d9ab898a0d10
Recommendation

Confirm that the hard-coded Feishu chat is the intended recipient and that these usage metrics are acceptable to share there.