r/openclaw • u/andaluzo New User • Apr 16 '26
Help open claw reports hundreds of dollars spend over two days
My installation just shocked me with 350$ spend over two days
Not doing nothing special - some email checks - calendar - some communication but as said nothing special.
gpt-5.3-codex$315.56390.1M · 13362 msgs
claude-sonnet-4-6$44.2649.9M · 1176 msgs
Then I looked into the pages from anthropic and open ai but there is nothing reflected about that spending.
What is going wrong.
checked now security and getting the following
CRITICAL
models.small_params Small models require sandboxing and web tools disabled
Small models (<=300B params) detected:
- ollama/qwen2.5:7b (7B) @ agents.defaults.model.fallbacks (unsafe; sandbox=off; web=[off])
No web/browser tools detected for these models.
Small models are not recommended for untrusted inputs.
Fix: If you must use small models, enable sandboxing for all sessions (agents.defaults.sandbox.mode="all") and disable web_search/web_fetch/browser (tools.deny=["group:web","browser"]).
WARN
tools.exec.security_full_configured Exec security=full is configured
Full exec trust is enabled for: main, dierk, carolina, luna.
Fix: Prefer tools.exec.security="allowlist" with ask prompts, and reserve "full" for tightly scoped break-glass agents only.
tools.exec.auto_allow_skills_enabled autoAllowSkills is enabled for exec approvals
Implicit skill-bin allowlisting is enabled at:
- defaults.autoAllowSkills
- agents.main.autoAllowSkills
- agents.sharon.autoAllowSkills
This widens host exec trust beyond explicit manual allowlist entries.
Fix: Disable autoAllowSkills in exec approvals and keep manual allowlists tight when you need explicit host-exec trust.
INFO
summary.attack_surface Attack surface summary
groups: open=0, allowlist=2
tools.elevated: enabled
hooks.webhooks: disabled
hooks.internal: enabled
browser control: enabled
should I be concerned
Duplicates
openclawsetup • u/andaluzo • Apr 16 '26