Agent Token Sentinel — 实用工具
v1.1.0用于 AI Agents. monitors API接口 usage 和 automatically kills recursive loops or excessive reasoning protect your wallet. O...
0· 479·1 当前·1 累计
安全扫描
OpenClaw
可疑
medium confidenceThe skill claims to monitor token usage and kill runaway agent loops, but it's instruction-only with no code, no declared permissions, and no concrete runtime instructions — the claimed capabilities don't match the actual footprint.
评估建议
This skill reads like a placeholder or marketing stub rather than a working guardian: it promises automatic token/loop control but provides no code, no required credentials, and no concrete runtime instructions. Before installing or relying on it, ask the author for: (1) the implementation (source code) showing how it reads usage metrics and terminates loops, (2) a list of exact permissions or environment variables it needs, and (3) what endpoints it contacts to send alerts. Because it currently...详细分析 ▾
⚠ 用途与能力
The README claims real-time monitoring, loop-killing, quota enforcement and notifications, yet the package declares no binaries, no credentials, no config paths, and contains no code — there is no clear mechanism by which it could perform those actions.
⚠ 指令范围
SKILL.md is high-level marketing text and a single CLI usage example; it provides no runtime instructions for how to observe API usage, kill processes, or send alerts. That vagueness grants broad, undefined discretion to the agent and is scope-creep (it claims powerful runtime actions but doesn't specify the safe, limited steps to do them).
✓ 安装机制
No install spec and no code files are present, which minimizes direct on-disk risk. However, absence of an install mechanism also means the skill can't transparently add the plumbing necessary to perform the claimed monitoring.
⚠ 凭证需求
No environment variables, credentials, or config paths are requested — yet the functionality would normally require access to agent API keys, usage meters, or process control permissions. This mismatch suggests the skill is incomplete or intentionally vague about required privileges.
ℹ 持久化与权限
always is false (normal) and the skill is user-invocable. It does not declare persistent system modifications, but because its claimed behavior would require elevated access (to agent runtime or tokens), lack of declared privileges is notable. There is currently no evidence it can actually act autonomously on system processes.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
安装命令
点击复制官方npx clawhub@latest install agent-token-sentinel
镜像加速npx clawhub@latest install agent-token-sentinel --registry https://cn.longxiaskill.com 镜像可用
本土化适配说明
Agent Token Sentinel — 实用工具 安装说明: 安装命令:["openclaw skills install agent-token-sentinel","npx clawhub@latest install agent-token-sentinel"]