安全扫描
OpenClaw
安全
high confidenceNULL
评估建议
This skill is an advisory playbook (no code), so installing it itself is low-risk. Before executing an audit guided by this skill: 1) Do not paste long-lived API keys, passwords, or raw billing exports into chats—use read-only or scoped/ephemeral keys where possible. 2) Run any model-comparison tests on anonymized or synthetic data or in a staging environment to avoid leaking PII. 3) Provide the agent only the minimum data needed (e.g., aggregated billing exports, usage reports) rather than full...详细分析 ▾
✓ 用途与能力
The name and description promise an AI spend audit; the SKILL.md provides a detailed, plausible framework (inventory, scoring, model optimization, vendor consolidation, reporting) that matches that purpose. There are no unrelated dependencies, binaries, or config requirements declared.
ℹ 指令范围
The instructions are largely advisory and procedural. They do recommend actions that, in practice, require access to billing data, API-based models, and production queries (e.g., 'run 100 production queries through a cheaper model' and mapping API-based tools). The skill itself does not include code to perform these operations nor does it request credentials — implementers will need to supply data and keys. This is scope-appropriate but important to note: carrying out the recommendations will require sensitive inputs from the user.
✓ 安装机制
No install spec and no code files are included; nothing is written to disk and there are no downloaded binaries. This is the lowest-risk installation profile.
ℹ 凭证需求
The skill declares no required environment variables or credentials, which is appropriate for an instruction-only framework. However, several suggested checks implicitly require access to API keys, billing exports, or production queries. Users must provide those credentials or data to perform the audit; the skill does not attempt to obtain them automatically.
✓ 持久化与权限
The skill does not request persistent presence (always:false), does not modify other skills, and contains no install steps that would alter agent/system configuration. Normal autonomous invocation remains possible but is not elevated by the skill itself.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/2/22
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install afrexai-ai-spend-audit
镜像加速npx clawhub@latest install afrexai-ai-spend-audit --registry https://cn.longxiaskill.com