Real Skill packageSource verifiedClawHub registry

TinkerClaw Token Panel

Know exactly where your AI tokens go. Multi-provider tracking, budget alerts, and a local REST API—all in one dashboard. Provider credentials are supplied by you and sealed in the OS keychain, never passed on a command line; it reads no other application's credential store. Transcript parsing, live provider probing, and reading another tool's API-key variables are each opt-in and off by default. Only counts are stored — no prompts, no task titles. See Permissions, Data Flow & Consent.

Identity and source

Publisher attributionOscar Serraregistry owner unverified by skillvetai
Functional categoryData, Spreadsheets & Analyticsautomatically inferred · 63% rule confidence
Package forminstruction with code22 recorded files
Canonical sourceClawHub registryclawhub:globalcaos:token-panel-ultimate
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/17/2026.claude/skills/token-panel-ultimate

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/17/2026.agents/skills/token-panel-ultimate

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/17/2026skills/token-panel-ultimate

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @globalcaos/token-panel-ultimate
clawhub inspect @globalcaos/token-panel-ultimate --version 2.6.2

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
22 / 22 inspected as text
Checked
9/17/2026, 5:03:13 PM
Scanner
0.1.3
Policy
1.0.3
3 automated findings
highInstructions or code access sensitive credential locationsSKILL.md:4 · confidence 85%keychain, never passed on a command line; it read
highInstructions or code access sensitive credential locationspackage.json:4 · confidence 85%keychain and never passed on a command line; no other application's credential store is read
highInstructions or code access sensitive credential locationsscripts/claude-usage-fetch.py:7 · confidence 85%keychain entry. It does not read
3 High/Critical review queue entries
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
Open human review queue →
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
16 dependency and API indicators
  • pypi: fastapi >=0.109.1,<1.0
  • pypi: uvicorn >=0.30.0,<1.0
  • pypi: httpx >=0.27.0,<1.0
  • pypi: pydantic >=2.7.0,<3.0
  • api: ai.google.dev
  • api: aistudio.google.com
  • api: api.anthropic.com
  • api: api.manus.ai
  • api: api.openai.com
  • api: claude.ai
  • api: console.anthropic.com
  • api: generativelanguage.googleapis.com
  • api: github.com
  • api: manus.im
  • api: platform.claude.com
  • api: platform.openai.com
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/17/2026, 12:12:04 PM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:c29c71725d7aea3b2baa37d35c7bd378b7d1f3ec2a37128ced054ab7faa3a008
Show up to 22 recorded paths
  • _meta.json
  • api.py
  • BUDGET_README.md
  • collector.py
  • db.py
  • package.json
  • parsers/__init__.py
  • parsers/anthropic.py
  • parsers/gemini.py
  • parsers/manus.py
  • parsers/transcript.py
  • requirements.txt
  • scripts/_secure_write.py
  • scripts/budget-panel-widget.user.js
  • scripts/chatgpt-usage-fetch.py
  • scripts/claude-usage-fetch.py
  • scripts/gemini-usage-fetch.py
  • scripts/manus-usage-fetch.py
  • secretstore.py
  • SKILL.md
  • tests/test_credentials.py
  • tests/test_file_safety.py

Source changelog

Added esc()/num(): every rendered string is HTML-escaped and every number coerced; Key now goes in the x-goog-api-key header; Split into separate slots: 'anthropic' (setup-token, no generic env var) and 'anthropic-admin' (TOKEN_PANEL_AN; Helpers now run by absolute path from /usr/bin or /bin only; Refuses a symlinked directory or file; Token compared with hmac; User-Agent is now token-panel-ultimate/2; Unit file text is now inside BUDGET_README as a heredoc

Release security diff

highCompared fixed releases 2.6.1 and 2.6.2; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • credential and domain expansion
  • dependency surface changed
  • file surface changed
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

2.6.19/9/2026sha256:2542d2a253eb931a9f9f8d0cabce6d967edab6d2ab44da1f5167605d15d4202e
2.6.09/8/2026sha256:0fa716586020832a6b7055cd5551e1a324571af392624fa3568ec6931f34d0a9
2.4.09/7/2026sha256:7aee971cf10f8e5b0c3800d80ad7d7dd86cea8b3d0f7a052d33d7635a90594af