{"id":"0a7f9dd3-c219-4848-a8b6-95073e776457","entityType":"agent","slug":"clawhub-vanhuelsing-openclaw-usage-dashboard","name":"OpenClaw Usage Dashboard","canonicalUrl":"https://www.xpersona.co/agent/clawhub-vanhuelsing-openclaw-usage-dashboard","canonicalPath":"/agent/clawhub-vanhuelsing-openclaw-usage-dashboard","generatedAt":"2026-10-09T11:10:59.397Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":null},"description":"Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Skill: OpenClaw Usage Dashboard Owner: vanhuelsing Summary: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Tags: latest:2.0.2 Version history: v2.0.2 | 2026-03-27T20:14:28.205Z | user Security fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 3.1K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17bee3dtgqmmy0yyryjm3n99183jep2:openclaw-usage-dashboard","sourceUrl":"https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard","homepage":"https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/vanhuelsing/openclaw-usage-dashboard","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":null},"stars":null,"forks":null,"downloads":3070,"packageName":null,"latestVersion":"2.0.2","tractionLabel":"3.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T09:57:27.065Z","lastCrawledAt":"2026-10-09T09:57:27.065Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T09:57:27.065Z","lastVerifiedAt":null,"highlights":[{"version":"2.0.2","createdAt":"2026-03-27T20:14:28.205Z","changelog":"Security fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (no shell). All execSync calls are hardcoded strings with zero variable interpolation.","fileCount":7,"zipByteSize":27595},{"version":"2.0.1","createdAt":"2026-03-27T20:10:35.434Z","changelog":"Security transparency: document child_process usage in source and README. All shell calls are fixed system commands (vm_stat, df, powershell, openclaw version) — no user input interpolation, all timeouts set, all wrapped in try/catch.","fileCount":6,"zipByteSize":26293},{"version":"2.0.0","createdAt":"2026-03-27T18:30:31.670Z","changelog":"v2.0 — Complete rewrite. Multi-model timeline with Models/Agents/Both toggle, model cards sorted by usage, agent activity heatmap, token efficiency metrics, system health (RAM VM-aware on macOS), period selector Hour/Day/Week/Month/Year. Cross-platform macOS/Linux/Windows. Zero dependencies, Node.js 18+. Security audit by Opus: XSS fix, CSP tightened, Intel Mac page size fix, Windows PowerShell fallback.","fileCount":6,"zipByteSize":25939},{"version":"1.0.1","createdAt":"2026-03-13T12:31:01.815Z","changelog":"Security fixes: removed unused subprocess import, added output path sanitization (VirusTotal scan feedback)","fileCount":4,"zipByteSize":21246},{"version":"1.0.0","createdAt":"2026-03-13T12:14:36.522Z","changelog":"Initial release — multi-provider usage dashboard with SVG charts, budget tracking, CSV export, demo mode","fileCount":4,"zipByteSize":21138}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17bee3dtgqmmy0yyryjm3n99183jep2:openclaw-usage-dashboard","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T11:10:59.396Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-vanhuelsing-openclaw-usage-dashboard/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":null},"readme":"Skill: OpenClaw Usage Dashboard\n\nOwner: vanhuelsing\n\nSummary: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down...\n\nTags: latest:2.0.2\n\nVersion history:\n\nv2.0.2 | 2026-03-27T20:14:28.205Z | user\n\nSecurity fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (no shell). All execSync calls are hardcoded strings with zero variable interpolation.\n\nv2.0.1 | 2026-03-27T20:10:35.434Z | user\n\nSecurity transparency: document child_process usage in source and README. All shell calls are fixed system commands (vm_stat, df, powershell, openclaw version) — no user input interpolation, all timeouts set, all wrapped in try/catch.\n\nv2.0.0 | 2026-03-27T18:30:31.670Z | user\n\nv2.0 — Complete rewrite. Multi-model timeline with Models/Agents/Both toggle, model cards sorted by usage, agent activity heatmap, token efficiency metrics, system health (RAM VM-aware on macOS), period selector Hour/Day/Week/Month/Year. Cross-platform macOS/Linux/Windows. Zero dependencies, Node.js 18+. Security audit by Opus: XSS fix, CSP tightened, Intel Mac page size fix, Windows PowerShell fallback.\n\nv1.0.1 | 2026-03-13T12:31:01.815Z | user\n\nSecurity fixes: removed unused subprocess import, added output path sanitization (VirusTotal scan feedback)\n\nv1.0.0 | 2026-03-13T12:14:36.522Z | user\n\nInitial release — multi-provider usage dashboard with SVG charts, budget tracking, CSV export, demo mode\n\nArchive index:\n\nArchive v2.0.2: 7 files, 27595 bytes\n\nFiles: AUDIT.md (6501b), dashboard.html (49638b), README.md (1930b), server.js (23208b), skill-card.md (2007b), SKILL.md (1872b), _meta.json (143b)\n\nFile v2.0.2:SKILL.md\n\n---\nname: openclaw-usage-dashboard\ndescription: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down by model, agent, and time period (hour/day/week/month/year). Reads session logs directly; no external service needed, data stays local. Use when a user asks about token usage, model activity, how many requests were made, usage by agent, system health, or wants a usage overview. Triggers on \"usage dashboard\", \"token usage\", \"how many requests\", \"model usage\", \"usage by agent\", \"usage stats\", \"system health\", \"ram usage\".\n---\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and shows token usage, model activity, and system health in real time. Runs entirely on localhost — no data ever leaves your machine.\n\n## Usage\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## What It Shows\n\n- **Timeline chart** — requests over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of requests per agent\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health** — RAM (VM-aware on macOS), disk, uptime, OpenClaw version\n- **Period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n\n## Requirements\n\n- Node.js 18+ (no `npm install` needed — zero external dependencies)\n- OpenClaw session logs at `~/.openclaw/agents/*/sessions/*.jsonl`\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\nFile v2.0.2:README.md\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and visualises token usage, model activity, and system health in real time. Runs entirely on your machine — no data ever leaves localhost.\n\n![Dashboard](references/screenshot.png)\n\n## Features\n\n- **Timeline chart** — token usage over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of which agent made how many requests\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health strip** — RAM (VM-aware on macOS), disk, uptime, and OpenClaw version\n- **Time period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n- **Dark theme** — `#0a0e1a` background with 🦞 favicon\n- **Localhost-only** — reads `~/.openclaw/agents/*/sessions/*.jsonl`; no network calls\n\n## Quick Start\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## Install via ClawHub\n\n```bash\nopenclaw skills install openclaw-usage-dashboard\n```\n\n## Requirements\n\n- Node.js 18+\n- No `npm install` needed — zero external dependencies\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\n## Security\n\n`server.js` uses `child_process.execSync` for **system health only** — fixed commands like `vm_stat`, `df`, `powershell` (disk/RAM info) and `openclaw version`. No user input is ever interpolated into a shell command. All calls have hard timeouts and try/catch wrappers. Data never leaves localhost.\n\n## Roadmap\n\n- Rate limits tracking — [GitHub issue #55934](https://github.com/openclaw/openclaw/issues/55934)\n\n## License\n\nMIT\n\nFile v2.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7f35f0wcgzrzem84ptabr0h182qszf\",\n  \"slug\": \"openclaw-usage-dashboard\",\n  \"version\": \"2.0.2\",\n  \"publishedAt\": 1774642468205\n}\n\nFile v2.0.2:AUDIT.md\n\n# OpenClaw Usage Dashboard v2.0 — Pre-Release Audit\n\n**Auditor:** Quality Agent (Senior Developer)  \n**Date:** 2026-03-27  \n**Files audited:** `server.js`, `dashboard.html`  \n**Verdict:** ✅ Ready to publish (after fixes applied below)\n\n---\n\n## Summary\n\nOverall, this is well-built code with solid security fundamentals — no raw secrets exposed, proper HTML escaping, localhost-only binding, and good defensive limits. The audit found **9 issues** (2 critical, 3 moderate, 4 minor), all of which have been fixed in-place.\n\n---\n\n## Issues Found & Fixed\n\n### 🔴 Critical\n\n#### C1. `modelIds` ReferenceError in chart tooltip handler\n**File:** `dashboard.html` (inside `drawChart`)  \n**Problem:** The `canvas.onmousemove` tooltip handler referenced `modelIds`, but `drawChart` is a standalone function — `modelIds` is only a parameter of `renderTimeline`, not in `drawChart`'s scope. Hovering over the chart would throw a `ReferenceError` every time.  \n**Fix:** Added `const chartModelIds = series.filter(s => !s.dashed && !s.id.startsWith('agent:')).map(s => s.id)` at the top of `drawChart`, and replaced `modelIds` with `chartModelIds` in the tooltip handler.\n\n#### C2. `getAgentColor()` returns `undefined` for unknown agents\n**File:** `dashboard.html`  \n**Problem:** When `dashData` is null or an agent ID isn't in `agentStats`, `keys.indexOf(id)` returns `-1`. `AGENT_PALETTE[-1 % 8]` evaluates to `AGENT_PALETTE[-1]` which is `undefined`. This would render `style=\"color:undefined\"` in CSS — invalid/broken.  \n**Fix:** Added `if (idx < 0) return AGENT_PALETTE[0]` fallback.\n\n### 🟡 Moderate\n\n#### M1. XSS via single quotes in `esc()` function\n**File:** `dashboard.html`  \n**Problem:** `esc()` escaped `<`, `>`, `&`, `\"` but NOT single quotes. Since legend items use `onclick=\"toggleSeries('...')\"` with single-quoted IDs, a model ID containing `'` could break out of the handler — an XSS vector.  \n**Fix:** Added `.replace(/'/g,'&#39;')` to `esc()`.\n\n#### M2. CSP allows `unsafe-eval` unnecessarily\n**File:** `server.js`  \n**Problem:** Content-Security-Policy included `'unsafe-eval'`, but no code uses `eval()`, `Function()`, or `setTimeout(string)`. This unnecessarily weakens CSP.  \n**Fix:** Removed `'unsafe-eval'` from the CSP directive. `'unsafe-inline'` is still needed for the inline `<script>` and `<style>`.\n\n#### M3. Windows `wmic` deprecated/removed\n**File:** `server.js`  \n**Problem:** Disk free space on Windows used `wmic logicaldisk`, which is deprecated in Windows 10 and removed in Windows 11. Would silently fail.  \n**Fix:** Added PowerShell `(Get-PSDrive C).Free` as the primary method, with `wmic` as fallback for older systems.\n\n### 🟢 Minor\n\n#### m1. `vm_stat` page size hardcoded to 16384\n**File:** `server.js`  \n**Problem:** Page size was hardcoded to 16384 (Apple Silicon). Intel Macs use 4096-byte pages. Memory calculation would be 4x too high on Intel.  \n**Fix:** Parse page size from `vm_stat` output header (`page size of N bytes`), fall back to 16384.\n\n#### m2. Double-escaped HTML in tooltip model breakdown\n**File:** `dashboard.html`  \n**Problem:** `modelBreakdown` was already built with `esc()` on each model name, then wrapped again with `esc(modelBreakdown)`. Characters like `&` would render as `&amp;amp;`.  \n**Fix:** Removed the outer `esc()` since the inner values are already escaped.\n\n#### m3. `openclaw version` shell command not Windows-compatible\n**File:** `server.js`  \n**Problem:** Used `||` and `2>/dev/null` (bash syntax) with `shell: true`, which on Windows invokes `cmd.exe` where these don't work.  \n**Fix:** Split into two separate `try/catch` blocks, each calling one variant without shell redirection.\n\n#### m4. Dead code cleanup\n**Files:** `server.js`, `dashboard.html`  \n- **`CHUNK_SIZE = 200`** (server.js) — defined but never used. Removed.\n- **`const alpha`** (dashboard.html, `renderHeatmap`) — computed but never used. Removed.\n- **`const labels = ''`** (dashboard.html, `renderHeatmap`) — assigned but never used. Removed.\n- **Heatmap color ternary dead branch** — `pct > 0.4 ? '56,189,248' : '56,189,248'` — both branches identical. Simplified to just `'56,189,248'`.\n\n---\n\n## Issues Noted (Not Fixed — Acceptable for v2.0)\n\n### N1. Synchronous file I/O on every API request\n`getAllSessionFiles` and `parseSessionFile` use `fs.readFileSync`/`fs.readdirSync`. For a local single-user dashboard this is fine — the `MAX_SESSIONS` (2000) and `MEMORY_BUDGET_MB` (100) limits prevent catastrophic blocking. Consider async I/O for v3 if scaling to multi-user.\n\n### N2. `parseInt()` without radix parameter\nMultiple `parseInt()` calls omit the radix argument. All inputs are known decimal strings from regex captures of `\\d+`, so this is functionally safe. Purely a lint-level concern.\n\n### N3. `sanitizeEntry()` / `sanitizeText()` defined but unused\nThese functions exist as defensive code for future config sanitization. The current code only exposes numeric aggregates (never raw log content), so they're not needed today. Kept as defense-in-depth.\n\n### N4. `configInfo` variable assigned but never read\nPopulated in `loadConfig()` but never referenced elsewhere. Presumably reserved for future features. Harmless.\n\n### N5. Auto-refresh interval not configurable\nThe 5-minute auto-refresh is hardcoded in dashboard.html. Not a problem, but could be a `--refresh-interval` flag for power users.\n\n---\n\n## Checklist Results\n\n| Category | Status |\n|---|---|\n| **macOS** | ✅ Works (with vm_stat page size fix) |\n| **Linux** | ✅ Works (os.freemem fallback is fine) |\n| **Windows** | ✅ Works (PowerShell + wmic fallback, separate version commands) |\n| **Node 18/20** | ✅ All features compatible (optional chaining since v14, catch binding since v10) |\n| **Port configurable** | ✅ `--port` CLI flag with clear error on EADDRINUSE |\n| **No secrets leaked** | ✅ `getConfig()` extracts only model metadata, never keys/tokens |\n| **XSS protection** | ✅ `esc()` covers all 5 HTML special chars; `textContent` used for error messages |\n| **Path traversal** | ✅ No user-controlled file paths in serving logic |\n| **CORS** | ✅ Restricted to `http://localhost:PORT` |\n| **CSP** | ✅ Tightened (removed `unsafe-eval`) |\n| **Error handling** | ✅ All file ops wrapped in try/catch, graceful fallbacks |\n| **Edge cases** | ✅ 0 data, 1 bucket, null dashData all handled |\n\n---\n\n## Files Modified\n\n- `server.js` — 5 surgical edits\n- `dashboard.html` — 6 surgical edits\n- `AUDIT.md` — this file (new)\n\nFile v2.0.2:skill-card.md\n\n## Description:\n\nOpenClaw Usage Dashboard provides a localhost dashboard for OpenClaw usage, model activity, token consumption, agent activity, and system health from local session logs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[vanhuelsing](https://clawhub.ai/user/vanhuelsing)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and OpenClaw users use this skill to launch a local dashboard that summarizes token usage, request counts, model and agent activity, cache efficiency, and system health from OpenClaw session logs.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Private OpenClaw usage patterns, model choices, agent names, session timing, and system details can be exposed through unauthenticated dashboard APIs.\n\nMitigation: Run only with the default localhost binding and do not use --host 0.0.0.0 or any other non-loopback address.\n\nRisk: Server evidence reports a verified browser security flaw and marks the release suspicious.\n\nMitigation: Review the skill before installing, especially on shared or networked machines, and use it only in a trusted local browser environment.\n\n## Reference(s):\n\n- [OpenClaw Usage Dashboard on ClawHub](https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard)\n- [OpenClaw Rate Limits Tracking Issue](https://github.com/openclaw/openclaw/issues/55934)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration]\n\n**Output Format:** [Markdown with inline shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide the user to run a local Node.js dashboard on a selected localhost port.]\n\n## Skill Version(s):\n\n2.0.2 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v2.0.1: 6 files, 26293 bytes\n\nFiles: AUDIT.md (6501b), dashboard.html (49638b), README.md (1930b), server.js (22770b), SKILL.md (1872b), _meta.json (143b)\n\nFile v2.0.1:SKILL.md\n\n---\nname: openclaw-usage-dashboard\ndescription: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down by model, agent, and time period (hour/day/week/month/year). Reads session logs directly; no external service needed, data stays local. Use when a user asks about token usage, model activity, how many requests were made, usage by agent, system health, or wants a usage overview. Triggers on \"usage dashboard\", \"token usage\", \"how many requests\", \"model usage\", \"usage by agent\", \"usage stats\", \"system health\", \"ram usage\".\n---\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and shows token usage, model activity, and system health in real time. Runs entirely on localhost — no data ever leaves your machine.\n\n## Usage\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## What It Shows\n\n- **Timeline chart** — requests over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of requests per agent\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health** — RAM (VM-aware on macOS), disk, uptime, OpenClaw version\n- **Period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n\n## Requirements\n\n- Node.js 18+ (no `npm install` needed — zero external dependencies)\n- OpenClaw session logs at `~/.openclaw/agents/*/sessions/*.jsonl`\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\nFile v2.0.1:README.md\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and visualises token usage, model activity, and system health in real time. Runs entirely on your machine — no data ever leaves localhost.\n\n![Dashboard](references/screenshot.png)\n\n## Features\n\n- **Timeline chart** — token usage over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of which agent made how many requests\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health strip** — RAM (VM-aware on macOS), disk, uptime, and OpenClaw version\n- **Time period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n- **Dark theme** — `#0a0e1a` background with 🦞 favicon\n- **Localhost-only** — reads `~/.openclaw/agents/*/sessions/*.jsonl`; no network calls\n\n## Quick Start\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## Install via ClawHub\n\n```bash\nopenclaw skills install openclaw-usage-dashboard\n```\n\n## Requirements\n\n- Node.js 18+\n- No `npm install` needed — zero external dependencies\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\n## Security\n\n`server.js` uses `child_process.execSync` for **system health only** — fixed commands like `vm_stat`, `df`, `powershell` (disk/RAM info) and `openclaw version`. No user input is ever interpolated into a shell command. All calls have hard timeouts and try/catch wrappers. Data never leaves localhost.\n\n## Roadmap\n\n- Rate limits tracking — [GitHub issue #55934](https://github.com/openclaw/openclaw/issues/55934)\n\n## License\n\nMIT\n\nFile v2.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7f35f0wcgzrzem84ptabr0h182qszf\",\n  \"slug\": \"openclaw-usage-dashboard\",\n  \"version\": \"2.0.1\",\n  \"publishedAt\": 1774642235434\n}\n\nFile v2.0.1:AUDIT.md\n\n# OpenClaw Usage Dashboard v2.0 — Pre-Release Audit\n\n**Auditor:** Quality Agent (Senior Developer)  \n**Date:** 2026-03-27  \n**Files audited:** `server.js`, `dashboard.html`  \n**Verdict:** ✅ Ready to publish (after fixes applied below)\n\n---\n\n## Summary\n\nOverall, this is well-built code with solid security fundamentals — no raw secrets exposed, proper HTML escaping, localhost-only binding, and good defensive limits. The audit found **9 issues** (2 critical, 3 moderate, 4 minor), all of which have been fixed in-place.\n\n---\n\n## Issues Found & Fixed\n\n### 🔴 Critical\n\n#### C1. `modelIds` ReferenceError in chart tooltip handler\n**File:** `dashboard.html` (inside `drawChart`)  \n**Problem:** The `canvas.onmousemove` tooltip handler referenced `modelIds`, but `drawChart` is a standalone function — `modelIds` is only a parameter of `renderTimeline`, not in `drawChart`'s scope. Hovering over the chart would throw a `ReferenceError` every time.  \n**Fix:** Added `const chartModelIds = series.filter(s => !s.dashed && !s.id.startsWith('agent:')).map(s => s.id)` at the top of `drawChart`, and replaced `modelIds` with `chartModelIds` in the tooltip handler.\n\n#### C2. `getAgentColor()` returns `undefined` for unknown agents\n**File:** `dashboard.html`  \n**Problem:** When `dashData` is null or an agent ID isn't in `agentStats`, `keys.indexOf(id)` returns `-1`. `AGENT_PALETTE[-1 % 8]` evaluates to `AGENT_PALETTE[-1]` which is `undefined`. This would render `style=\"color:undefined\"` in CSS — invalid/broken.  \n**Fix:** Added `if (idx < 0) return AGENT_PALETTE[0]` fallback.\n\n### 🟡 Moderate\n\n#### M1. XSS via single quotes in `esc()` function\n**File:** `dashboard.html`  \n**Problem:** `esc()` escaped `<`, `>`, `&`, `\"` but NOT single quotes. Since legend items use `onclick=\"toggleSeries('...')\"` with single-quoted IDs, a model ID containing `'` could break out of the handler — an XSS vector.  \n**Fix:** Added `.replace(/'/g,'&#39;')` to `esc()`.\n\n#### M2. CSP allows `unsafe-eval` unnecessarily\n**File:** `server.js`  \n**Problem:** Content-Security-Policy included `'unsafe-eval'`, but no code uses `eval()`, `Function()`, or `setTimeout(string)`. This unnecessarily weakens CSP.  \n**Fix:** Removed `'unsafe-eval'` from the CSP directive. `'unsafe-inline'` is still needed for the inline `<script>` and `<style>`.\n\n#### M3. Windows `wmic` deprecated/removed\n**File:** `server.js`  \n**Problem:** Disk free space on Windows used `wmic logicaldisk`, which is deprecated in Windows 10 and removed in Windows 11. Would silently fail.  \n**Fix:** Added PowerShell `(Get-PSDrive C).Free` as the primary method, with `wmic` as fallback for older systems.\n\n### 🟢 Minor\n\n#### m1. `vm_stat` page size hardcoded to 16384\n**File:** `server.js`  \n**Problem:** Page size was hardcoded to 16384 (Apple Silicon). Intel Macs use 4096-byte pages. Memory calculation would be 4x too high on Intel.  \n**Fix:** Parse page size from `vm_stat` output header (`page size of N bytes`), fall back to 16384.\n\n#### m2. Double-escaped HTML in tooltip model breakdown\n**File:** `dashboard.html`  \n**Problem:** `modelBreakdown` was already built with `esc()` on each model name, then wrapped again with `esc(modelBreakdown)`. Characters like `&` would render as `&amp;amp;`.  \n**Fix:** Removed the outer `esc()` since the inner values are already escaped.\n\n#### m3. `openclaw version` shell command not Windows-compatible\n**File:** `server.js`  \n**Problem:** Used `||` and `2>/dev/null` (bash syntax) with `shell: true`, which on Windows invokes `cmd.exe` where these don't work.  \n**Fix:** Split into two separate `try/catch` blocks, each calling one variant without shell redirection.\n\n#### m4. Dead code cleanup\n**Files:** `server.js`, `dashboard.html`  \n- **`CHUNK_SIZE = 200`** (server.js) — defined but never used. Removed.\n- **`const alpha`** (dashboard.html, `renderHeatmap`) — computed but never used. Removed.\n- **`const labels = ''`** (dashboard.html, `renderHeatmap`) — assigned but never used. Removed.\n- **Heatmap color ternary dead branch** — `pct > 0.4 ? '56,189,248' : '56,189,248'` — both branches identical. Simplified to just `'56,189,248'`.\n\n---\n\n## Issues Noted (Not Fixed — Acceptable for v2.0)\n\n### N1. Synchronous file I/O on every API request\n`getAllSessionFiles` and `parseSessionFile` use `fs.readFileSync`/`fs.readdirSync`. For a local single-user dashboard this is fine — the `MAX_SESSIONS` (2000) and `MEMORY_BUDGET_MB` (100) limits prevent catastrophic blocking. Consider async I/O for v3 if scaling to multi-user.\n\n### N2. `parseInt()` without radix parameter\nMultiple `parseInt()` calls omit the radix argument. All inputs are known decimal strings from regex captures of `\\d+`, so this is functionally safe. Purely a lint-level concern.\n\n### N3. `sanitizeEntry()` / `sanitizeText()` defined but unused\nThese functions exist as defensive code for future config sanitization. The current code only exposes numeric aggregates (never raw log content), so they're not needed today. Kept as defense-in-depth.\n\n### N4. `configInfo` variable assigned but never read\nPopulated in `loadConfig()` but never referenced elsewhere. Presumably reserved for future features. Harmless.\n\n### N5. Auto-refresh interval not configurable\nThe 5-minute auto-refresh is hardcoded in dashboard.html. Not a problem, but could be a `--refresh-interval` flag for power users.\n\n---\n\n## Checklist Results\n\n| Category | Status |\n|---|---|\n| **macOS** | ✅ Works (with vm_stat page size fix) |\n| **Linux** | ✅ Works (os.freemem fallback is fine) |\n| **Windows** | ✅ Works (PowerShell + wmic fallback, separate version commands) |\n| **Node 18/20** | ✅ All features compatible (optional chaining since v14, catch binding since v10) |\n| **Port configurable** | ✅ `--port` CLI flag with clear error on EADDRINUSE |\n| **No secrets leaked** | ✅ `getConfig()` extracts only model metadata, never keys/tokens |\n| **XSS protection** | ✅ `esc()` covers all 5 HTML special chars; `textContent` used for error messages |\n| **Path traversal** | ✅ No user-controlled file paths in serving logic |\n| **CORS** | ✅ Restricted to `http://localhost:PORT` |\n| **CSP** | ✅ Tightened (removed `unsafe-eval`) |\n| **Error handling** | ✅ All file ops wrapped in try/catch, graceful fallbacks |\n| **Edge cases** | ✅ 0 data, 1 bucket, null dashData all handled |\n\n---\n\n## Files Modified\n\n- `server.js` — 5 surgical edits\n- `dashboard.html` — 6 surgical edits\n- `AUDIT.md` — this file (new)\n\nArchive v2.0.0: 6 files, 25939 bytes\n\nFiles: AUDIT.md (6501b), dashboard.html (49638b), README.md (1614b), server.js (22353b), SKILL.md (1872b), _meta.json (143b)\n\nFile v2.0.0:SKILL.md\n\n---\nname: openclaw-usage-dashboard\ndescription: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down by model, agent, and time period (hour/day/week/month/year). Reads session logs directly; no external service needed, data stays local. Use when a user asks about token usage, model activity, how many requests were made, usage by agent, system health, or wants a usage overview. Triggers on \"usage dashboard\", \"token usage\", \"how many requests\", \"model usage\", \"usage by agent\", \"usage stats\", \"system health\", \"ram usage\".\n---\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and shows token usage, model activity, and system health in real time. Runs entirely on localhost — no data ever leaves your machine.\n\n## Usage\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## What It Shows\n\n- **Timeline chart** — requests over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of requests per agent\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health** — RAM (VM-aware on macOS), disk, uptime, OpenClaw version\n- **Period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n\n## Requirements\n\n- Node.js 18+ (no `npm install` needed — zero external dependencies)\n- OpenClaw session logs at `~/.openclaw/agents/*/sessions/*.jsonl`\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\nFile v2.0.0:README.md\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and visualises token usage, model activity, and system health in real time. Runs entirely on your machine — no data ever leaves localhost.\n\n![Dashboard](references/screenshot.png)\n\n## Features\n\n- **Timeline chart** — token usage over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of which agent made how many requests\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health strip** — RAM (VM-aware on macOS), disk, uptime, and OpenClaw version\n- **Time period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n- **Dark theme** — `#0a0e1a` background with 🦞 favicon\n- **Localhost-only** — reads `~/.openclaw/agents/*/sessions/*.jsonl`; no network calls\n\n## Quick Start\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## Install via ClawHub\n\n```bash\nopenclaw skills install openclaw-usage-dashboard\n```\n\n## Requirements\n\n- Node.js 18+\n- No `npm install` needed — zero external dependencies\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\n## Roadmap\n\n- Rate limits tracking — [GitHub issue #55934](https://github.com/openclaw/openclaw/issues/55934)\n\n## License\n\nMIT\n\nFile v2.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7f35f0wcgzrzem84ptabr0h182qszf\",\n  \"slug\": \"openclaw-usage-dashboard\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1774636231670\n}\n\nFile v2.0.0:AUDIT.md\n\n# OpenClaw Usage Dashboard v2.0 — Pre-Release Audit\n\n**Auditor:** Quality Agent (Senior Developer)  \n**Date:** 2026-03-27  \n**Files audited:** `server.js`, `dashboard.html`  \n**Verdict:** ✅ Ready to publish (after fixes applied below)\n\n---\n\n## Summary\n\nOverall, this is well-built code with solid security fundamentals — no raw secrets exposed, proper HTML escaping, localhost-only binding, and good defensive limits. The audit found **9 issues** (2 critical, 3 moderate, 4 minor), all of which have been fixed in-place.\n\n---\n\n## Issues Found & Fixed\n\n### 🔴 Critical\n\n#### C1. `modelIds` ReferenceError in chart tooltip handler\n**File:** `dashboard.html` (inside `drawChart`)  \n**Problem:** The `canvas.onmousemove` tooltip handler referenced `modelIds`, but `drawChart` is a standalone function — `modelIds` is only a parameter of `renderTimeline`, not in `drawChart`'s scope. Hovering over the chart would throw a `ReferenceError` every time.  \n**Fix:** Added `const chartModelIds = series.filter(s => !s.dashed && !s.id.startsWith('agent:')).map(s => s.id)` at the top of `drawChart`, and replaced `modelIds` with `chartModelIds` in the tooltip handler.\n\n#### C2. `getAgentColor()` returns `undefined` for unknown agents\n**File:** `dashboard.html`  \n**Problem:** When `dashData` is null or an agent ID isn't in `agentStats`, `keys.indexOf(id)` returns `-1`. `AGENT_PALETTE[-1 % 8]` evaluates to `AGENT_PALETTE[-1]` which is `undefined`. This would render `style=\"color:undefined\"` in CSS — invalid/broken.  \n**Fix:** Added `if (idx < 0) return AGENT_PALETTE[0]` fallback.\n\n### 🟡 Moderate\n\n#### M1. XSS via single quotes in `esc()` function\n**File:** `dashboard.html`  \n**Problem:** `esc()` escaped `<`, `>`, `&`, `\"` but NOT single quotes. Since legend items use `onclick=\"toggleSeries('...')\"` with single-quoted IDs, a model ID containing `'` could break out of the handler — an XSS vector.  \n**Fix:** Added `.replace(/'/g,'&#39;')` to `esc()`.\n\n#### M2. CSP allows `unsafe-eval` unnecessarily\n**File:** `server.js`  \n**Problem:** Content-Security-Policy included `'unsafe-eval'`, but no code uses `eval()`, `Function()`, or `setTimeout(string)`. This unnecessarily weakens CSP.  \n**Fix:** Removed `'unsafe-eval'` from the CSP directive. `'unsafe-inline'` is still needed for the inline `<script>` and `<style>`.\n\n#### M3. Windows `wmic` deprecated/removed\n**File:** `server.js`  \n**Problem:** Disk free space on Windows used `wmic logicaldisk`, which is deprecated in Windows 10 and removed in Windows 11. Would silently fail.  \n**Fix:** Added PowerShell `(Get-PSDrive C).Free` as the primary method, with `wmic` as fallback for older systems.\n\n### 🟢 Minor\n\n#### m1. `vm_stat` page size hardcoded to 16384\n**File:** `server.js`  \n**Problem:** Page size was hardcoded to 16384 (Apple Silicon). Intel Macs use 4096-byte pages. Memory calculation would be 4x too high on Intel.  \n**Fix:** Parse page size from `vm_stat` output header (`page size of N bytes`), fall back to 16384.\n\n#### m2. Double-escaped HTML in tooltip model breakdown\n**File:** `dashboard.html`  \n**Problem:** `modelBreakdown` was already built with `esc()` on each model name, then wrapped again with `esc(modelBreakdown)`. Characters like `&` would render as `&amp;amp;`.  \n**Fix:** Removed the outer `esc()` since the inner values are already escaped.\n\n#### m3. `openclaw version` shell command not Windows-compatible\n**File:** `server.js`  \n**Problem:** Used `||` and `2>/dev/null` (bash syntax) with `shell: true`, which on Windows invokes `cmd.exe` where these don't work.  \n**Fix:** Split into two separate `try/catch` blocks, each calling one variant without shell redirection.\n\n#### m4. Dead code cleanup\n**Files:** `server.js`, `dashboard.html`  \n- **`CHUNK_SIZE = 200`** (server.js) — defined but never used. Removed.\n- **`const alpha`** (dashboard.html, `renderHeatmap`) — computed but never used. Removed.\n- **`const labels = ''`** (dashboard.html, `renderHeatmap`) — assigned but never used. Removed.\n- **Heatmap color ternary dead branch** — `pct > 0.4 ? '56,189,248' : '56,189,248'` — both branches identical. Simplified to just `'56,189,248'`.\n\n---\n\n## Issues Noted (Not Fixed — Acceptable for v2.0)\n\n### N1. Synchronous file I/O on every API request\n`getAllSessionFiles` and `parseSessionFile` use `fs.readFileSync`/`fs.readdirSync`. For a local single-user dashboard this is fine — the `MAX_SESSIONS` (2000) and `MEMORY_BUDGET_MB` (100) limits prevent catastrophic blocking. Consider async I/O for v3 if scaling to multi-user.\n\n### N2. `parseInt()` without radix parameter\nMultiple `parseInt()` calls omit the radix argument. All inputs are known decimal strings from regex captures of `\\d+`, so this is functionally safe. Purely a lint-level concern.\n\n### N3. `sanitizeEntry()` / `sanitizeText()` defined but unused\nThese functions exist as defensive code for future config sanitization. The current code only exposes numeric aggregates (never raw log content), so they're not needed today. Kept as defense-in-depth.\n\n### N4. `configInfo` variable assigned but never read\nPopulated in `loadConfig()` but never referenced elsewhere. Presumably reserved for future features. Harmless.\n\n### N5. Auto-refresh interval not configurable\nThe 5-minute auto-refresh is hardcoded in dashboard.html. Not a problem, but could be a `--refresh-interval` flag for power users.\n\n---\n\n## Checklist Results\n\n| Category | Status |\n|---|---|\n| **macOS** | ✅ Works (with vm_stat page size fix) |\n| **Linux** | ✅ Works (os.freemem fallback is fine) |\n| **Windows** | ✅ Works (PowerShell + wmic fallback, separate version commands) |\n| **Node 18/20** | ✅ All features compatible (optional chaining since v14, catch binding since v10) |\n| **Port configurable** | ✅ `--port` CLI flag with clear error on EADDRINUSE |\n| **No secrets leaked** | ✅ `getConfig()` extracts only model metadata, never keys/tokens |\n| **XSS protection** | ✅ `esc()` covers all 5 HTML special chars; `textContent` used for error messages |\n| **Path traversal** | ✅ No user-controlled file paths in serving logic |\n| **CORS** | ✅ Restricted to `http://localhost:PORT` |\n| **CSP** | ✅ Tightened (removed `unsafe-eval`) |\n| **Error handling** | ✅ All file ops wrapped in try/catch, graceful fallbacks |\n| **Edge cases** | ✅ 0 data, 1 bucket, null dashData all handled |\n\n---\n\n## Files Modified\n\n- `server.js` — 5 surgical edits\n- `dashboard.html` — 6 surgical edits\n- `AUDIT.md` — this file (new)\n\nArchive v1.0.1: 4 files, 21246 bytes\n\nFiles: references/prices.md (3211b), scripts/usage-dashboard-generic.py (70436b), SKILL.md (2504b), _meta.json (143b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: openclaw-usage-dashboard\ndescription: Generate an interactive local HTML dashboard showing OpenClaw API usage, costs, and rate-limit quotas across multiple LLM providers (Anthropic, OpenAI, Google, Moonshot, Mistral, Cohere, Groq). Reads session transcripts directly — no external service needed. Use when a user asks about API costs, token usage, model spend, quota/rate limits, usage by model or time period, or wants a cost overview dashboard. Triggers on \"usage dashboard\", \"API kosten\", \"wie viel kostet\", \"kontingent\", \"rate limit\", \"token verbrauch\", \"cost dashboard\", \"openclaw costs\", \"spending overview\".\n---\n\n# OpenClaw Usage Dashboard\n\nGenerate a self-contained HTML dashboard from OpenClaw session transcripts. Zero dependencies — Python 3.8+ stdlib only.\n\n## Usage\n\n```bash\n# Real data (reads ~/.openclaw/agents/main/sessions/)\npython3 scripts/usage-dashboard-generic.py [output.html]\n\n# Demo mode (generates 30 days of realistic mock data)\npython3 scripts/usage-dashboard-generic.py [output.html] --demo\n```\n\nDefault output: `~/openclaw-usage-dashboard.html`\n\nOverride sessions path: set `OPENCLAW_ROOT` env var.\n\n## What It Shows\n\n- **Cost KPIs**: Total spend, today's cost, API calls, active model, cache hit rate, monthly projection\n- **Model config**: Active / default / fallback models from `openclaw.json`\n- **Anthropic quota gauges**: 5h and 7d rate limit utilization (requires `ANTHROPIC_API_KEY`)\n- **Donut chart**: Cost distribution by model\n- **Hourly sparkline**: Today's call volume by hour\n- **Stacked bars**: Cost by period (daily / weekly / monthly / yearly)\n- **Model table**: Per-model breakdown with token counts and cost\n- **Detail table + chart**: Toggle between table and bar chart view per period\n- **Budget tracker**: Set monthly limit, progress bar, localStorage persistence\n- **CSV export**: Download any period view as CSV\n- **Provider dropdown**: Filter by provider\n\n## Supported Providers\n\nAnthropic, OpenAI, Google, Moonshot/Kimi, Mistral, Cohere, Groq — 30+ models with built-in pricing.\n\n## Customization\n\n### Add models\n\nEdit `PRICES` dict in the script (price per 1M tokens):\n\n```python\n\"provider/model-name\": {\"input\": 2.50, \"output\": 10.00, \"cache_read\": 1.25, \"cache_write\": 2.50}\n```\n\nAdd to `MODEL_COLORS` and `ALIAS_MAP` as needed.\n\n### Pricing reference\n\nSee `references/prices.md` for current prices across all providers.\n\n## Requirements\n\n- Python 3.8+ (stdlib only)\n- `ANTHROPIC_API_KEY` in env (optional, for live quota gauges)\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7f35f0wcgzrzem84ptabr0h182qszf\",\n  \"slug\": \"openclaw-usage-dashboard\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1773405061815\n}\n\nFile v1.0.1:references/prices.md\n\n# Multi-Provider Pricing Reference\n\n> **Stand: März 2026** — Preise in USD pro 1M Tokens.  \n> Diese Datei dokumentiert die im Skill unterstützten Provider und Preise.\n\n## Preis-Updates\n\nWenn sich Preise ändern oder neue Modelle hinzukommen:\n\n1. **Direkt im Script** (`scripts/usage-dashboard-generic.py` oder `usage-dashboard.py`):\n   - `PRICES` Dictionary erweitern\n   - `MODEL_COLORS` erweitern (für Visualisierung)\n   - Optional: `ALIAS_MAP` erweitern (für kurze Modellnamen)\n\n2. **Diese Datei aktualisieren** mit neuen Preisen und Quellen\n\n---\n\n## Anthropic\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| claude-opus-4-6 | $15.00 | $75.00 | $1.50 | $18.75 |\n| claude-sonnet-4-6 | $3.00 | $15.00 | $0.30 | $3.75 |\n| claude-sonnet-4-5 | $3.00 | $15.00 | $0.30 | $3.75 |\n| claude-haiku-4-5 | $0.80 | $4.00 | $0.08 | $1.00 |\n\n🔗 https://www.anthropic.com/pricing\n\n---\n\n## OpenAI\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| gpt-4o | $2.50 | $10.00 | $1.25 | $2.50 |\n| gpt-4o-mini | $0.15 | $0.60 | $0.075 | $0.15 |\n| o3-mini | $1.10 | $4.40 | $0.55 | $1.10 |\n| o1 | $15.00 | $60.00 | $7.50 | $15.00 |\n| o1-mini | $1.10 | $4.40 | $0.55 | $1.10 |\n\n🔗 https://platform.openai.com/docs/pricing\n\n---\n\n## Google (Gemini)\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| gemini-2.0-flash | $0.10 | $0.40 | $0.025 | $0.10 |\n| gemini-2.0-pro | $3.50 | $10.50 | $0.875 | $3.50 |\n| gemini-1.5-pro | $1.25 | $5.00 | $0.312 | $1.25 |\n| gemini-1.5-flash | $0.075 | $0.30 | $0.019 | $0.075 |\n\n🔗 https://ai.google.dev/pricing\n\n---\n\n## Moonshot / Kimi\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| kimi-k2.5 | $0.00* | $0.00* | $0.00* | $0.00* |\n| moonshot-v1-8k | $0.00* | $0.00* | $0.00* | $0.00* |\n\n> *Preise werden nicht per API geloggt — $0.00 als Platzhalter.  \n> Tatsächliche Preise: https://platform.moonshot.cn/pricing\n\n---\n\n## Mistral AI\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| mistral-large-latest | $2.00 | $6.00 | $0.50 | $2.00 |\n| mistral-medium | $0.60 | $1.80 | $0.15 | $0.60 |\n| mistral-small | $0.10 | $0.30 | $0.025 | $0.10 |\n| codestral | $0.20 | $0.60 | $0.05 | $0.20 |\n\n🔗 https://mistral.ai/technology/#pricing\n\n---\n\n## Cohere\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| command-r-plus | $2.50 | $10.00 | $0.625 | $2.50 |\n| command-r | $0.50 | $1.50 | $0.125 | $0.50 |\n\n🔗 https://cohere.com/pricing\n\n---\n\n## Groq\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| llama-3.3-70b-versatile | $0.59 | $0.79 | — | — |\n| llama-3.1-8b-instant | $0.05 | $0.08 | — | — |\n| gemma2-9b-it | $0.20 | $0.40 | — | — |\n\n> Ultra-schnelle Inference, kein Caching  \n> 🔗 https://groq.com/pricing/\n\n---\n\n## Hinweise\n\n- **Cache-Preise** gelten nur wenn Prompt Caching vom Modell unterstützt und aktiv ist\n- **Groq**: Kein Caching verfügbar, Preise pro 1M Input/Output Tokens\n- **Moonshot**: Preise werden nicht in OpenClaw Session-Logs gespeichert — Dashboard zeigt $0.00\n- Preise können sich ändern — immer offizielle Provider-Seiten prüfen\n\nArchive v1.0.0: 4 files, 21138 bytes\n\nFiles: references/prices.md (3211b), scripts/usage-dashboard-generic.py (70187b), SKILL.md (2504b), _meta.json (143b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: openclaw-usage-dashboard\ndescription: Generate an interactive local HTML dashboard showing OpenClaw API usage, costs, and rate-limit quotas across multiple LLM providers (Anthropic, OpenAI, Google, Moonshot, Mistral, Cohere, Groq). Reads session transcripts directly — no external service needed. Use when a user asks about API costs, token usage, model spend, quota/rate limits, usage by model or time period, or wants a cost overview dashboard. Triggers on \"usage dashboard\", \"API kosten\", \"wie viel kostet\", \"kontingent\", \"rate limit\", \"token verbrauch\", \"cost dashboard\", \"openclaw costs\", \"spending overview\".\n---\n\n# OpenClaw Usage Dashboard\n\nGenerate a self-contained HTML dashboard from OpenClaw session transcripts. Zero dependencies — Python 3.8+ stdlib only.\n\n## Usage\n\n```bash\n# Real data (reads ~/.openclaw/agents/main/sessions/)\npython3 scripts/usage-dashboard-generic.py [output.html]\n\n# Demo mode (generates 30 days of realistic mock data)\npython3 scripts/usage-dashboard-generic.py [output.html] --demo\n```\n\nDefault output: `~/openclaw-usage-dashboard.html`\n\nOverride sessions path: set `OPENCLAW_ROOT` env var.\n\n## What It Shows\n\n- **Cost KPIs**: Total spend, today's cost, API calls, active model, cache hit rate, monthly projection\n- **Model config**: Active / default / fallback models from `openclaw.json`\n- **Anthropic quota gauges**: 5h and 7d rate limit utilization (requires `ANTHROPIC_API_KEY`)\n- **Donut chart**: Cost distribution by model\n- **Hourly sparkline**: Today's call volume by hour\n- **Stacked bars**: Cost by period (daily / weekly / monthly / yearly)\n- **Model table**: Per-model breakdown with token counts and cost\n- **Detail table + chart**: Toggle between table and bar chart view per period\n- **Budget tracker**: Set monthly limit, progress bar, localStorage persistence\n- **CSV export**: Download any period view as CSV\n- **Provider dropdown**: Filter by provider\n\n## Supported Providers\n\nAnthropic, OpenAI, Google, Moonshot/Kimi, Mistral, Cohere, Groq — 30+ models with built-in pricing.\n\n## Customization\n\n### Add models\n\nEdit `PRICES` dict in the script (price per 1M tokens):\n\n```python\n\"provider/model-name\": {\"input\": 2.50, \"output\": 10.00, \"cache_read\": 1.25, \"cache_write\": 2.50}\n```\n\nAdd to `MODEL_COLORS` and `ALIAS_MAP` as needed.\n\n### Pricing reference\n\nSee `references/prices.md` for current prices across all providers.\n\n## Requirements\n\n- Python 3.8+ (stdlib only)\n- `ANTHROPIC_API_KEY` in env (optional, for live quota gauges)\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7f35f0wcgzrzem84ptabr0h182qszf\",\n  \"slug\": \"openclaw-usage-dashboard\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1773404076522\n}\n\nFile v1.0.0:references/prices.md\n\n# Multi-Provider Pricing Reference\n\n> **Stand: März 2026** — Preise in USD pro 1M Tokens.  \n> Diese Datei dokumentiert die im Skill unterstützten Provider und Preise.\n\n## Preis-Updates\n\nWenn sich Preise ändern oder neue Modelle hinzukommen:\n\n1. **Direkt im Script** (`scripts/usage-dashboard-generic.py` oder `usage-dashboard.py`):\n   - `PRICES` Dictionary erweitern\n   - `MODEL_COLORS` erweitern (für Visualisierung)\n   - Optional: `ALIAS_MAP` erweitern (für kurze Modellnamen)\n\n2. **Diese Datei aktualisieren** mit neuen Preisen und Quellen\n\n---\n\n## Anthropic\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| claude-opus-4-6 | $15.00 | $75.00 | $1.50 | $18.75 |\n| claude-sonnet-4-6 | $3.00 | $15.00 | $0.30 | $3.75 |\n| claude-sonnet-4-5 | $3.00 | $15.00 | $0.30 | $3.75 |\n| claude-haiku-4-5 | $0.80 | $4.00 | $0.08 | $1.00 |\n\n🔗 https://www.anthropic.com/pricing\n\n---\n\n## OpenAI\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| gpt-4o | $2.50 | $10.00 | $1.25 | $2.50 |\n| gpt-4o-mini | $0.15 | $0.60 | $0.075 | $0.15 |\n| o3-mini | $1.10 | $4.40 | $0.55 | $1.10 |\n| o1 | $15.00 | $60.00 | $7.50 | $15.00 |\n| o1-mini | $1.10 | $4.40 | $0.55 | $1.10 |\n\n🔗 https://platform.openai.com/docs/pricing\n\n---\n\n## Google (Gemini)\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| gemini-2.0-flash | $0.10 | $0.40 | $0.025 | $0.10 |\n| gemini-2.0-pro | $3.50 | $10.50 | $0.875 | $3.50 |\n| gemini-1.5-pro | $1.25 | $5.00 | $0.312 | $1.25 |\n| gemini-1.5-flash | $0.075 | $0.30 | $0.019 | $0.075 |\n\n🔗 https://ai.google.dev/pricing\n\n---\n\n## Moonshot / Kimi\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| kimi-k2.5 | $0.00* | $0.00* | $0.00* | $0.00* |\n| moonshot-v1-8k | $0.00* | $0.00* | $0.00* | $0.00* |\n\n> *Preise werden nicht per API geloggt — $0.00 als Platzhalter.  \n> Tatsächliche Preise: https://platform.moonshot.cn/pricing\n\n---\n\n## Mistral AI\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| mistral-large-latest | $2.00 | $6.00 | $0.50 | $2.00 |\n| mistral-medium | $0.60 | $1.80 | $0.15 | $0.60 |\n| mistral-small | $0.10 | $0.30 | $0.025 | $0.10 |\n| codestral | $0.20 | $0.60 | $0.05 | $0.20 |\n\n🔗 https://mistral.ai/technology/#pricing\n\n---\n\n## Cohere\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| command-r-plus | $2.50 | $10.00 | $0.625 | $2.50 |\n| command-r | $0.50 | $1.50 | $0.125 | $0.50 |\n\n🔗 https://cohere.com/pricing\n\n---\n\n## Groq\n\n| Modell | Input | Output | Cache Read | Cache Write |\n|---|---|---|---|---|\n| llama-3.3-70b-versatile | $0.59 | $0.79 | — | — |\n| llama-3.1-8b-instant | $0.05 | $0.08 | — | — |\n| gemma2-9b-it | $0.20 | $0.40 | — | — |\n\n> Ultra-schnelle Inference, kein Caching  \n> 🔗 https://groq.com/pricing/\n\n---\n\n## Hinweise\n\n- **Cache-Preise** gelten nur wenn Prompt Caching vom Modell unterstützt und aktiv ist\n- **Groq**: Kein Caching verfügbar, Preise pro 1M Input/Output Tokens\n- **Moonshot**: Preise werden nicht in OpenClaw Session-Logs gespeichert — Dashboard zeigt $0.00\n- Preise können sich ändern — immer offizielle Provider-Seiten prüfen","readmeExcerpt":"Skill: OpenClaw Usage Dashboard Owner: vanhuelsing Summary: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Tags: latest:2.0.2 Version history: v2.0.2 | 2026-03-27T20:14:28.205Z | user Security fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"node server.js"},{"language":"bash","snippet":"node server.js --port 8080"},{"language":"bash","snippet":"node server.js"},{"language":"bash","snippet":"node server.js --port 8080"},{"language":"bash","snippet":"openclaw skills install openclaw-usage-dashboard"},{"language":"bash","snippet":"node server.js"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: openclaw-usage-dashboard\ndescription: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down by model, agent, and time period (hour/day/week/month/year). Reads session logs directly; no external service needed, data stays local. Use when a user asks about token usage, model activity, how many requests were made, usage by agent, system health, or wants a usage overview. Triggers on \"usage dashboard\", \"token usage\", \"how many requests\", \"model usage\", \"usage by agent\", \"usage stats\", \"system health\", \"ram usage\".\n---\n\n# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and shows token usage, model activity, and system health in real time. Runs entirely on localhost — no data ever leaves your machine.\n\n## Usage\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## What It Shows\n\n- **Timeline chart** — requests over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of requests per agent\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health** — RAM (VM-aware on macOS), disk, uptime, OpenClaw version\n- **Period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n\n## Requirements\n\n- Node.js 18+ (no `npm install` needed — zero external dependencies)\n- OpenClaw session logs at `~/.openclaw/agents/*/sessions/*.jsonl`\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |"},{"path":"README.md","content":"# OpenClaw Usage Dashboard\n\nA zero-dependency Node.js dashboard that reads your OpenClaw session logs and visualises token usage, model activity, and system health in real time. Runs entirely on your machine — no data ever leaves localhost.\n\n![Dashboard](references/screenshot.png)\n\n## Features\n\n- **Timeline chart** — token usage over time with Models / Agents / Both filter toggle\n- **Model cards** — token counts and request counts per model, sorted by most used\n- **Agent activity** — breakdown of which agent made how many requests\n- **Session heatmap** — activity distribution by hour of day\n- **Token efficiency** — cache hit ratio and average prompt size\n- **System health strip** — RAM (VM-aware on macOS), disk, uptime, and OpenClaw version\n- **Time period selector** — Hour / Day / Week / Month / Year (keyboard shortcuts `1`–`5`)\n- **Dark theme** — `#0a0e1a` background with 🦞 favicon\n- **Localhost-only** — reads `~/.openclaw/agents/*/sessions/*.jsonl`; no network calls\n\n## Quick Start\n\n```bash\nnode server.js\n```\n\nOpen **http://localhost:7842** in your browser.\n\n### Custom port\n\n```bash\nnode server.js --port 8080\n```\n\n## Install via ClawHub\n\n```bash\nopenclaw skills install openclaw-usage-dashboard\n```\n\n## Requirements\n\n- Node.js 18+\n- No `npm install` needed — zero external dependencies\n\n## Platform Support\n\n| Platform | Supported |\n|----------|-----------|\n| macOS    | ✅        |\n| Linux    | ✅        |\n| Windows  | ✅        |\n\n## Security\n\n`server.js` uses `child_process.execSync` for **system health only** — fixed commands like `vm_stat`, `df`, `powershell` (disk/RAM info) and `openclaw version`. No user input is ever interpolated into a shell command. All calls have hard timeouts and try/catch wrappers. Data never leaves localhost.\n\n## Roadmap\n\n- Rate limits tracking — [GitHub issue #55934](https://github.com/openclaw/openclaw/issues/55934)\n\n## License\n\nMIT"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7f35f0wcgzrzem84ptabr0h182qszf\",\n  \"slug\": \"openclaw-usage-dashboard\",\n  \"version\": \"2.0.2\",\n  \"publishedAt\": 1774642468205\n}"},{"path":"AUDIT.md","content":"# OpenClaw Usage Dashboard v2.0 — Pre-Release Audit\n\n**Auditor:** Quality Agent (Senior Developer)  \n**Date:** 2026-03-27  \n**Files audited:** `server.js`, `dashboard.html`  \n**Verdict:** ✅ Ready to publish (after fixes applied below)\n\n---\n\n## Summary\n\nOverall, this is well-built code with solid security fundamentals — no raw secrets exposed, proper HTML escaping, localhost-only binding, and good defensive limits. The audit found **9 issues** (2 critical, 3 moderate, 4 minor), all of which have been fixed in-place.\n\n---\n\n## Issues Found & Fixed\n\n### 🔴 Critical\n\n#### C1. `modelIds` ReferenceError in chart tooltip handler\n**File:** `dashboard.html` (inside `drawChart`)  \n**Problem:** The `canvas.onmousemove` tooltip handler referenced `modelIds`, but `drawChart` is a standalone function — `modelIds` is only a parameter of `renderTimeline`, not in `drawChart`'s scope. Hovering over the chart would throw a `ReferenceError` every time.  \n**Fix:** Added `const chartModelIds = series.filter(s => !s.dashed && !s.id.startsWith('agent:')).map(s => s.id)` at the top of `drawChart`, and replaced `modelIds` with `chartModelIds` in the tooltip handler.\n\n#### C2. `getAgentColor()` returns `undefined` for unknown agents\n**File:** `dashboard.html`  \n**Problem:** When `dashData` is null or an agent ID isn't in `agentStats`, `keys.indexOf(id)` returns `-1`. `AGENT_PALETTE[-1 % 8]` evaluates to `AGENT_PALETTE[-1]` which is `undefined`. This would render `style=\"color:undefined\"` in CSS — invalid/broken.  \n**Fix:** Added `if (idx < 0) return AGENT_PALETTE[0]` fallback.\n\n### 🟡 Moderate\n\n#### M1. XSS via single quotes in `esc()` function\n**File:** `dashboard.html`  \n**Problem:** `esc()` escaped `<`, `>`, `&`, `\"` but NOT single quotes. Since legend items use `onclick=\"toggleSeries('...')\"` with single-quoted IDs, a model ID containing `'` could break out of the handler — an XSS vector.  \n**Fix:** Added `.replace(/'/g,'&#39;')` to `esc()`.\n\n#### M2. CSP allows `unsafe-eval` unnecessarily\n**File:** `server.js`  \n**Problem:** Content-Security-Policy included `'unsafe-eval'`, but no code uses `eval()`, `Function()`, or `setTimeout(string)`. This unnecessarily weakens CSP.  \n**Fix:** Removed `'unsafe-eval'` from the CSP directive. `'unsafe-inline'` is still needed for the inline `<script>` and `<style>`.\n\n#### M3. Windows `wmic` deprecated/removed\n**File:** `server.js`  \n**Problem:** Disk free space on Windows used `wmic logicaldisk`, which is deprecated in Windows 10 and removed in Windows 11. Would silently fail.  \n**Fix:** Added PowerShell `(Get-PSDrive C).Free` as the primary method, with `wmic` as fallback for older systems.\n\n### 🟢 Minor\n\n#### m1. `vm_stat` page size hardcoded to 16384\n**File:** `server.js`  \n**Problem:** Page size was hardcoded to 16384 (Apple Silicon). Intel Macs use 4096-byte pages. Memory calculation would be 4x too high on Intel.  \n**Fix:** Parse page size from `vm_stat` output header (`page size of N bytes`), fall back to 16384.\n\n#### m2. Doub"},{"path":"skill-card.md","content":"## Description:\n\nOpenClaw Usage Dashboard provides a localhost dashboard for OpenClaw usage, model activity, token consumption, agent activity, and system health from local session logs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[vanhuelsing](https://clawhub.ai/user/vanhuelsing)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and OpenClaw users use this skill to launch a local dashboard that summarizes token usage, request counts, model and agent activity, cache efficiency, and system health from OpenClaw session logs.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Private OpenClaw usage patterns, model choices, agent names, session timing, and system details can be exposed through unauthenticated dashboard APIs.\n\nMitigation: Run only with the default localhost binding and do not use --host 0.0.0.0 or any other non-loopback address.\n\nRisk: Server evidence reports a verified browser security flaw and marks the release suspicious.\n\nMitigation: Review the skill before installing, especially on shared or networked machines, and use it only in a trusted local browser environment.\n\n## Reference(s):\n\n- [OpenClaw Usage Dashboard on ClawHub](https://clawhub.ai/vanhuelsing/skills/openclaw-usage-dashboard)\n- [OpenClaw Rate Limits Tracking Issue](https://github.com/openclaw/openclaw/issues/55934)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration]\n\n**Output Format:** [Markdown with inline shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide the user to run a local Node.js dashboard on a selected localhost port.]\n\n## Skill Version(s):\n\n2.0.2 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Skill: OpenClaw Usage Dashboard Owner: vanhuelsing Summary: Interactive local dashboard for OpenClaw API usage. Shows token consumption, request counts, and system health across all configured LLM models — broken down... Tags: latest:2.0.2 Version history: v2.0.2 | 2026-03-27T20:14:28.205Z | user Security fix: patch shell injection vulnerability. --open flag and df disk check now use spawn/spawnSync with array args (","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1649,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:57:27.065Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:10:59.397Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}