Back to skill

Security audit

OpenClaw Cost Guardian

Security checks for vulnerabilities and agentic risk

Overview

This cost-monitoring skill is purpose-aligned, but it asks to automatically monitor conversations, send daily reports, and potentially change cost-related behavior without clear opt-in or boundaries.

Review before installing if you are not comfortable with a skill inspecting OpenClaw usage patterns across conversations. Use it manually for reports and recommendations unless the publisher adds explicit opt-in controls, report destinations, retention/deletion details, and confirmation before changing models or pausing tasks.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrase at this location is overly broad and can be invoked during ordinary conversation outside the skill's intended context. This can cause unintended activation of a skill that monitors usage and influences model selection, leading to surprise behavior and possible exposure of cost/usage information within unrelated sessions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
This trigger phrase lacks clear domain scoping and is likely to overlap with common requests a user might make in many contexts. In a skill that claims automatic monitoring and reporting, accidental activation increases the risk of collecting or surfacing usage data without clear user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The phrase is ambiguous and common enough to match unrelated user requests, making accidental invocation plausible. Because the skill advertises automatic recommendations, monitoring, and reporting, such unintended activation can create confusion, privacy concerns, and unauthorized workflow changes.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill says it will 'automatically run,' 'automatically monitor every conversation,' and 'send daily cost reports' without a clear upfront warning or consent flow. Automatic monitoring and reporting of usage data can affect privacy expectations and may expose sensitive metadata about user activity, especially if reports are sent or surfaced without explicit authorization.

Static analysis

No suspicious patterns detected.