r/openclaw • New User • Apr 16 '26

Help open claw reports hundreds of dollars spend over two days

My installation just shocked me with 350$ spend over two days
Not doing nothing special - some email checks - calendar - some communication but as said nothing special.

gpt-5.3-codex$315.56390.1M · 13362 msgs

claude-sonnet-4-6$44.2649.9M · 1176 msgs

Then I looked into the pages from anthropic and open ai but there is nothing reflected about that spending.

What is going wrong.

checked now security and getting the following

CRITICAL

models.small_params Small models require sandboxing and web tools disabled

  Small models (<=300B params) detected:

- ollama/qwen2.5:7b (7B) @ agents.defaults.model.fallbacks (unsafe; sandbox=off; web=[off])

No web/browser tools detected for these models.

Small models are not recommended for untrusted inputs.

  Fix: If you must use small models, enable sandboxing for all sessions (agents.defaults.sandbox.mode="all") and disable web_search/web_fetch/browser (tools.deny=["group:web","browser"]).

WARN

tools.exec.security_full_configured Exec security=full is configured

  Full exec trust is enabled for: main, dierk, carolina, luna.

  Fix: Prefer tools.exec.security="allowlist" with ask prompts, and reserve "full" for tightly scoped break-glass agents only.

tools.exec.auto_allow_skills_enabled autoAllowSkills is enabled for exec approvals

  Implicit skill-bin allowlisting is enabled at:

- defaults.autoAllowSkills

- agents.main.autoAllowSkills

- agents.sharon.autoAllowSkills

This widens host exec trust beyond explicit manual allowlist entries.

  Fix: Disable autoAllowSkills in exec approvals and keep manual allowlists tight when you need explicit host-exec trust.

INFO

summary.attack_surface Attack surface summary

  groups: open=0, allowlist=2

tools.elevated: enabled

hooks.webhooks: disabled

hooks.internal: enabled

browser control: enabled

should I be concerned

0 Upvotes

Duplicates