Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The script defaults to reading secrets and operational parameters from $HOME/.openclaw/skills/aave-delegation even though the skill is named agent-credit. This can cause the repay action to use the wrong RPC endpoint, private key, delegator, pool, or asset mappings, leading to repayment or approvals being executed against unintended accounts or contracts. In a blockchain repayment skill, misbinding configuration is especially dangerous because the resulting transactions are irreversible and may expose funds or credentials across skill boundaries.
