OpenClaw Usage Dashboard
Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Skill: OpenClaw Usage Dashboard Owner: vanhuelsing Summary: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Tags: latest:2.0.2 Version history: v2.0.2 | 2026-03-27T20:14:28.205Z | user Security fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (
Rank
62
Safety
84
Downloads
3.1k
Updated
Oct 9, 2026
Version
2.0.2
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 3.1K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 3.1K downloadsadoption · observed Oct 9, 2026
- Latest release
- 2.0.2release · observed Mar 27, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bee3dtgqmmy0yyryjm3n99183jep2:openclaw-usage-dashboard- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/snapshot"
Documentation
CLAWHUB
47,139 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: openclaw-usage-dashboard description: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down by model, agent, and time period (hour/day/week/month/year). Reads session logs directly; no external service needed, data stays local. Use when a user asks about token usage, model activity, how many requests were made, usage by agent, system health, or wants a usage overview. Triggers on "usage dashboard", "token usage", "how many requests", "model usage", "usage by agent", "usage stats", "system health", "ram usage". --- # OpenClaw Usage Dashboard A zero-dependency Node.js dashboard that reads your OpenClaw session logs and shows token usage, model activity, and system health in real time. Runs entirely on localhost — no data ever leaves your machine. ## Usage ```bash node server.js ``` Open **http://localhost:7842** in your browser. ### Custom port ```bash node server.js --port 8080 ``` ## What It Shows - **Timeline chart** — requests over time with Models / Agents / Both filter toggle - **Model cards** — token counts and request counts per model, sorted by most used - **Agent activity** — breakdown of requests per agent - **Session heatmap** — activity distribution by hour of day - **Token efficiency** — cache hit ratio and average prompt size - **System health** — RAM (VM-aware on macOS), disk, uptime, OpenClaw version - **Period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`) ## Requirements - Node.js 18+ (no `npm install` needed — zero external dependencies) - OpenClaw session logs at `~/.openclaw/agents/*/sessions/*.jsonl` ## Platform Support | Platform | Supported | |----------|-----------| | macOS | ✅ | | Linux | ✅ | | Windows | ✅ |
README.md
# OpenClaw Usage Dashboard A zero-dependency Node.js dashboard that reads your OpenClaw session logs and visualises token usage, model activity, and system health in real time. Runs entirely on your machine — no data ever leaves localhost.  ## Features - **Timeline chart** — token usage over time with Models / Agents / Both filter toggle - **Model cards** — token counts and request counts per model, sorted by most used - **Agent activity** — breakdown of which agent made how many requests - **Session heatmap** — activity distribution by hour of day - **Token efficiency** — cache hit ratio and average prompt size - **System health strip** — RAM (VM-aware on macOS), disk, uptime, and OpenClaw version - **Time period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`) - **Dark theme** — `#0a0e1a` background with 🦞 favicon - **Localhost-only** — reads `~/.openclaw/agents/*/sessions/*.jsonl`; no network calls ## Quick Start ```bash node server.js ``` Open **http://localhost:7842** in your browser. ### Custom port ```bash node server.js --port 8080 ``` ## Install via ClawHub ```bash openclaw skills install openclaw-usage-dashboard ``` ## Requirements - Node.js 18+ - No `npm install` needed — zero external dependencies ## Platform Support | Platform | Supported | |----------|-----------| | macOS | ✅ | | Linux | ✅ | | Windows | ✅ | ## Security `server.js` uses `child_process.execSync` for **system health only** — fixed commands like `vm_stat`, `df`, `powershell` (disk/RAM info) and `openclaw version`. No user input is ever interpolated into a shell command. All calls have hard timeouts and try/catch wrappers. Data never leaves localhost. ## Roadmap - Rate limits tracking — [GitHub issue #55934](https://github.com/openclaw/openclaw/issues/55934) ## License MIT
_meta.json
{
"ownerId": "kn7f35f0wcgzrzem84ptabr0h182qszf",
"slug": "openclaw-usage-dashboard",
"version": "2.0.2",
"publishedAt": 1774642468205
}AUDIT.md
# OpenClaw Usage Dashboard v2.0 — Pre-Release Audit
**Auditor:** Quality Agent (Senior Developer)
**Date:** 2026-03-27
**Files audited:** `server.js`, `dashboard.html`
**Verdict:** ✅ Ready to publish (after fixes applied below)
---
## Summary
Overall, this is well-built code with solid security fundamentals — no raw secrets exposed, proper HTML escaping, localhost-only binding, and good defensive limits. The audit found **9 issues** (2 critical, 3 moderate, 4 minor), all of which have been fixed in-place.
---
## Issues Found & Fixed
### 🔴 Critical
#### C1. `modelIds` ReferenceError in chart tooltip handler
**File:** `dashboard.html` (inside `drawChart`)
**Problem:** The `canvas.onmousemove` tooltip handler referenced `modelIds`, but `drawChart` is a standalone function — `modelIds` is only a parameter of `renderTimeline`, not in `drawChart`'s scope. Hovering over the chart would throw a `ReferenceError` every time.
**Fix:** Added `const chartModelIds = series.filter(s => !s.dashed && !s.id.startsWith('agent:')).map(s => s.id)` at the top of `drawChart`, and replaced `modelIds` with `chartModelIds` in the tooltip handler.
#### C2. `getAgentColor()` returns `undefined` for unknown agents
**File:** `dashboard.html`
**Problem:** When `dashData` is null or an agent ID isn't in `agentStats`, `keys.indexOf(id)` returns `-1`. `AGENT_PALETTE[-1 % 8]` evaluates to `AGENT_PALETTE[-1]` which is `undefined`. This would render `style="color:undefined"` in CSS — invalid/broken.
**Fix:** Added `if (idx < 0) return AGENT_PALETTE[0]` fallback.
### 🟡 Moderate
#### M1. XSS via single quotes in `esc()` function
**File:** `dashboard.html`
**Problem:** `esc()` escaped `<`, `>`, `&`, `"` but NOT single quotes. Since legend items use `onclick="toggleSeries('...')"` with single-quoted IDs, a model ID containing `'` could break out of the handler — an XSS vector.
**Fix:** Added `.replace(/'/g,''')` to `esc()`.
#### M2. CSP allows `unsafe-eval` unnecessarily
**File:** `server.js`
**Problem:** Content-Security-Policy included `'unsafe-eval'`, but no code uses `eval()`, `Function()`, or `setTimeout(string)`. This unnecessarily weakens CSP.
**Fix:** Removed `'unsafe-eval'` from the CSP directive. `'unsafe-inline'` is still needed for the inline `<script>` and `<style>`.
#### M3. Windows `wmic` deprecated/removed
**File:** `server.js`
**Problem:** Disk free space on Windows used `wmic logicaldisk`, which is deprecated in Windows 10 and removed in Windows 11. Would silently fail.
**Fix:** Added PowerShell `(Get-PSDrive C).Free` as the primary method, with `wmic` as fallback for older systems.
### 🟢 Minor
#### m1. `vm_stat` page size hardcoded to 16384
**File:** `server.js`
**Problem:** Page size was hardcoded to 16384 (Apple Silicon). Intel Macs use 4096-byte pages. Memory calculation would be 4x too high on Intel.
**Fix:** Parse page size from `vm_stat` output header (`page size of N bytes`), fall back to 16384.
#### m2. Doubskill-card.md
## Description: OpenClaw Usage Dashboard provides a localhost dashboard for OpenClaw usage, model activity, token consumption, agent activity, and system health from local session logs. This skill is ready for commercial/non-commercial use. ## Publisher: [vanhuelsing](https://clawhub.ai/user/vanhuelsing) ### License/Terms of Use: MIT-0 ## Use Case: Developers and OpenClaw users use this skill to launch a local dashboard that summarizes token usage, request counts, model and agent activity, cache efficiency, and system health from OpenClaw session logs. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Private OpenClaw usage patterns, model choices, agent names, session timing, and system details can be exposed through unauthenticated dashboard APIs. Mitigation: Run only with the default localhost binding and do not use --host 0.0.0.0 or any other non-loopback address. Risk: Server evidence reports a verified browser security flaw and marks the release suspicious. Mitigation: Review the skill before installing, especially on shared or networked machines, and use it only in a trusted local browser environment. ## Reference(s): - [OpenClaw Usage Dashboard on ClawHub](https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard) - [OpenClaw Rate Limits Tracking Issue](https://github.com/openclaw/openclaw/issues/55934) ## Skill Output: **Output Type(s):** [Guidance, Shell commands, Configuration] **Output Format:** [Markdown with inline shell commands] **Output Parameters:** [1D] **Other Properties Related to Output:** [May guide the user to run a local Node.js dashboard on a selected localhost port.] ## Skill Version(s): 2.0.2 (source: server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard",
"sourceUrl": "https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T09:57:27.065Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T09:57:27.065Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "3.1K downloads",
"href": "https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard",
"sourceUrl": "https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T09:57:27.065Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.2",
"href": "https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard",
"sourceUrl": "https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-03-27T20:14:28.205Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.2",
"description": "Security fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (no shell). All execSync calls are hardcoded strings with zero variable interpolation.",
"href": "https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard",
"sourceUrl": "https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-03-27T20:14:28.205Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
