Back to skill

Security audit

OpenClaw Watch Dog

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its watchdog purpose, but it installs a persistent service, keeps sensitive unused API keys if supplied, and can run broad unpinned package installs, so users should review it carefully before installing.

Install only if you want a persistent OpenClaw watchdog that can restart the gateway and send Telegram alerts. Do not provide OpenAI or Anthropic API keys, rotate the Telegram bot token if it may have appeared in logs, and review the unpinned aiohttp and npm openclaw install behavior before enabling automatic recovery.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:81
Finding

Unpinned Packages Are Installed from Mutable External Registries

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh:81-84, scripts/watchdog.py:211-218, openclaw-watchdog/scripts/setup.sh:68-71, openclaw-watchdog/scripts/watchdog.py:211-218
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
info "Setting up Python virtual environment"
python3 -m venv "$VENV_DIR"
"$VENV_DIR/bin/pip" install --quiet --upgrade pip
"$VENV_DIR/bin/pip" install --quiet aiohttp
python
log.info("User approved reinstall, running npm install -g openclaw...")
APPROVE_REINSTALL.unlink(missing_ok=True)
await send_telegram(session, cfg, "🔧 <b>Watch Dog:</b> Reinstalling OpenClaw (approved by user)...")
try:
    subprocess.run(["npm", "install", "-g", "openclaw"], timeout=120,
                   capture_output=True, text=True)
    await asyncio.sleep(5)
    subprocess.run(["openclaw", "gateway", "start"], timeout=30,
                   capture_output=True, text=True)

Technical Analysis

The setup script upgrades pip and installs the latest resolvable aiohttp package without an exact version or integrity hash. The recovery routine similarly installs the current openclaw release globally from npm without specifying a known-good version or verifying package integrity.

No malicious package was identified during this static audit. The vulnerability is that the effective installation payload can change after the Skill has been reviewed. A compromised registry account, malicious upstream release, dependency compromise, or unexpected breaking release could cause arbitrary package installation code to execute under the user's account.

The npm operation requires explicit approval through ~/.openclaw/watchdog/approve-reinstall, which reduces the likelihood of exploitation but does not protect the integrity of the downloaded package.

Attack Path

  1. An attacker compromises an upstream ...[truncated 1110 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin aiohttp and all transitive dependencies to reviewed versions.
  2. Use a lockfile or requirements file with cryptographic hashes, such as pip install --require-hashes -r requirements.txt.
  3. Do not upgrade pip automatically during installation; use a tested minimum version and fail with clear instructions if it is unavailable.
  4. Record the currently installed OpenClaw version and reinstall that exact known-good version rather than the unconstrained latest release.
  5. Verify npm package provenance or integrity before installation.
  6. Prefer a user-scoped, isolated installation over npm install -g.
  7. Require renewed, operation-specific user confirmation that displays the exact package version and source before reinstalling.
  8. Check subprocess return codes before claiming recovery succeeded.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:22
Finding

Unused OpenAI and Anthropic API Keys Are Accepted and Stored

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh:22-29,45-47,95-102, openclaw-watchdog/scripts/setup.sh:22-35,82-89, references/troubleshooting.md:14, openclaw-watchdog/references/troubleshooting.md:14
Vulnerability Type: Unnecessary collection and retention of sensitive credentials
Risk Level: Medium

Vulnerable Code

bash
TELEGRAM_TOKEN="" TELEGRAM_CHAT_ID="" OPENAI_KEY="" ANTHROPIC_KEY="" GATEWAY_PORT=""

while [[ $# -gt 0 ]]; do
    case "$1" in
        --telegram-token)  TELEGRAM_TOKEN="$2";  shift 2 ;;
        --telegram-chat-id) TELEGRAM_CHAT_ID="$2"; shift 2 ;;
        --openai-key)      OPENAI_KEY="$2";      shift 2 ;;
        --anthropic-key)   ANTHROPIC_KEY="$2";   shift 2 ;;
        --gateway-port)    GATEWAY_PORT="$2";    shift 2 ;;
        *) error "Unknown argument: $1" ;;
    esac
done
bash
# AI keys are optional (used for future extensions only)
bash
CONFIG_JSON=$(python3 -c "
import json, sys
print(json.dumps({
    'telegram_token': sys.argv[1],
    'telegram_chat_id': sys.argv[2],
    'openai_key': sys.argv[3],
    'anthropic_key': sys.argv[4]
}))
" "$TELEGRAM_TOKEN" "$TELEGRAM_CHAT_ID" "$OPENAI_KEY" "$ANTHROPIC_KEY")

The troubleshooting documentation also recommends the unused option:

bash
~/.openclaw/workspace/openclaw-watchdog/scripts/setup.sh --telegram-token "..." --telegram-chat-id "..." --openai-key "..."

Technical Analysis

The watchdog performs local pattern-based diagnostics and does not use OpenAI or Anthropic APIs. Nevertheless, both installers accept corresponding API keys and retain them in config.enc for unspecified future extensions.

Collecting credentials that have no current function exceeds the minimum privileges and data requirements of the declared monitoring feature. Although the resulting file is encrypted and assigned mode 0600, the secrets first pass through command-line ...[truncated 1409 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove --openai-key and --anthropic-key from both installer copies.
  2. Remove the corresponding fields from the stored configuration.
  3. Remove the OpenAI key example from both troubleshooting documents.
  4. Do not request credentials for speculative future functionality.
  5. If a future feature genuinely requires these keys, introduce it through a separate, explicit consent flow.
  6. Store future credentials in the platform credential manager, such as macOS Keychain or a Linux secret service.
  7. Accept secrets through protected standard input or a secure file descriptor rather than command-line arguments.
  8. Provide migration logic that removes already stored unused keys when users upgrade.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/validate.py:5
Finding

Telegram Bot Credentials Are Passed Through Process Arguments and Embedded in Request URLs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:45-61, scripts/setup.sh:22-27, scripts/validate.py:5-18, scripts/test-message.py:5-29, with equivalent code in openclaw-watchdog/
Vulnerability Type: Sensitive credential exposure through command-line arguments and URLs
Risk Level: Low

Vulnerable Code

bash
python3 ~/.openclaw/workspace/openclaw-watchdog/scripts/validate.py "$TELEGRAM_TOKEN"
bash
~/.openclaw/workspace/openclaw-watchdog/scripts/setup.sh \
  --telegram-token "$TELEGRAM_TOKEN" \
  --telegram-chat-id "$TELEGRAM_CHAT_ID" \
  --gateway-port "$GATEWAY_PORT"
bash
python3 ~/.openclaw/workspace/openclaw-watchdog/scripts/test-message.py "$TELEGRAM_TOKEN" "$TELEGRAM_CHAT_ID"
python
token = sys.argv[1]

# Validate token format (digits:alphanumeric)
import re
if not re.match(r'^\d+:[A-Za-z0-9_-]+$', token):
    print("Error: Token format invalid. Expected format: 123456:ABC-DEF...", file=sys.stderr)
    sys.exit(1)

try:
    resp = json.loads(urllib.request.urlopen(f'https://api.telegram.org/bot{token}/getMe').read())
python
req = urllib.request.Request(
    f'https://api.telegram.org/bot{token}/sendMessage',
    data=data,
    headers={'Content-Type': 'application/json'}
)

Technical Analysis

The documented setup flow passes the Telegram bot token and chat ID as command-line arguments. Process arguments may be visible to process-monitoring utilities, same-user processes, diagnostic tooling, terminal records, or agent execution logs while the commands run.

Telegram's Bot API requires the token as part of the API URL, so transmission to https://api.telegram.org is expected and necessary for the declared alert functionality. The audit found no unauthorized destination and no covert exfiltration. However, URL-embedded secrets can be disclosed by verbose HTTP diagnostics, exception reporting, proxy logs, or monitoring sys ...[truncated 1201 chars]

Remediation
View remediation

Remediation Suggestions

  1. Read the bot token from protected standard input using a non-echoing prompt.
  2. Alternatively, use a mode-0600 credential file or operating-system credential manager.
  3. Avoid including secret values in shell commands generated by the Skill.
  4. Ensure agent, terminal, and subprocess logging redacts Telegram token patterns.
  5. Disable verbose HTTP logging for requests whose paths contain Telegram bot tokens.
  6. Keep error messages from printing complete request URLs.
  7. Document token rotation and immediate revocation procedures.
  8. Where feasible, isolate Telegram API request construction in a component that guarantees URL redaction in logs and exceptions.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (111)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill requests a Telegram bot token, passes it on the command line, and reaches out to api.telegram.org, yet the declared value proposition is OpenClaw monitoring and recovery. When a skill's real sensitive operation is credential handling plus external transmission, description-behavior mismatch materially increases phishing and unauthorized data-use risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill requests a Telegram bot token, passes it on the command line, and reaches out to api.telegram.org, yet the declared value proposition is OpenClaw monitoring and recovery. When a skill's real sensitive operation is credential handling plus external transmission, description-behavior mismatch materially increases phishing and unauthorized data-use risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill requests a Telegram bot token, passes it on the command line, and reaches out to api.telegram.org, yet the declared value proposition is OpenClaw monitoring and recovery. When a skill's real sensitive operation is credential handling plus external transmission, description-behavior mismatch materially increases phishing and unauthorized data-use risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill requests a Telegram bot token, passes it on the command line, and reaches out to api.telegram.org, yet the declared value proposition is OpenClaw monitoring and recovery. When a skill's real sensitive operation is credential handling plus external transmission, description-behavior mismatch materially increases phishing and unauthorized data-use risk.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

bash
if [[ "$(uname)" == "Darwin" ]]; then
  launchctl unload ~/Library/LaunchAgents/com.openclaw.watchdog.plist 2>/dev/null
  rm -f ~/Library/LaunchAgents/com.openclaw.watchdog.plist
else
  systemctl --user stop openclaw-watchdog 2>/dev/null
  systemctl --user disable openclaw-watchdog 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-watchdog/SKILL.md (reported line 95)May include surrounding context.

bash
if [[ "$(uname)" == "Darwin" ]]; then
  launchctl unload ~/Library/LaunchAgents/com.openclaw.watchdog.plist 2>/dev/null
  rm -f ~/Library/LaunchAgents/com.openclaw.watchdog.plist
else
  systemctl --user stop openclaw-watchdog 2>/dev/null
  systemctl --user disable openclaw-watchdog 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

else systemctl --user stop openclaw-watchdog 2>/dev/null systemctl --user disable openclaw-watchdog 2>/dev/null rm -f ~/.config/systemd/user/openclaw-watchdog.service fi rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-watchdog/SKILL.md (reported line 99)May include surrounding context.

else systemctl --user stop openclaw-watchdog 2>/dev/null systemctl --user disable openclaw-watchdog 2>/dev/null rm -f ~/.config/systemd/user/openclaw-watchdog.service fi rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The explicit 'rm -rf ~/.openclaw/watchdog' command is a destructive recursive deletion step. In a troubleshooting document, such commands can be dangerous because users may execute them without understanding they remove local watchdog state, logs, and configuration, increasing the chance of irreversible loss and operational outage.

Content

Scanner excerpt · openclaw-watchdog/references/troubleshooting.md (reported line 71)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The explicit 'rm -rf ~/.openclaw/watchdog' command is a destructive recursive deletion step. In a troubleshooting document, such commands can be dangerous because users may execute them without understanding they remove local watchdog state, logs, and configuration, increasing the chance of irreversible loss and operational outage.

Content

Scanner excerpt · openclaw-watchdog/references/troubleshooting.md (reported line 71)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The watchdog includes autonomous capability to reinstall software globally, which is substantially more dangerous than simple monitoring or restarting. In this skill context, that broadens the blast radius to package execution, persistence changes, and supply-chain compromise if the package source or local environment is manipulated.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-watchdog/references/troubleshooting.md (reported line 63)May include surrounding context.

bash
# macOS
launchctl unload ~/Library/LaunchAgents/com.openclaw.watchdog.plist
rm ~/Library/LaunchAgents/com.openclaw.watchdog.plist

# Linux
systemctl --user stop openclaw-watchdog

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 63)May include surrounding context.

bash
# macOS
launchctl unload ~/Library/LaunchAgents/com.openclaw.watchdog.plist
rm ~/Library/LaunchAgents/com.openclaw.watchdog.plist

# Linux
systemctl --user stop openclaw-watchdog

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-watchdog/references/troubleshooting.md (reported line 68)May include surrounding context.

md
# Linux
systemctl --user stop openclaw-watchdog
systemctl --user disable openclaw-watchdog
rm ~/.config/systemd/user/openclaw-watchdog.service

# Both
rm -rf ~/.openclaw/watchdog

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 68)May include surrounding context.

md
# Linux
systemctl --user stop openclaw-watchdog
systemctl --user disable openclaw-watchdog
rm ~/.config/systemd/user/openclaw-watchdog.service

# Both
rm -rf ~/.openclaw/watchdog

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-watchdog/SKILL.md (reported line 101)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 71)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-watchdog/SKILL.md (reported line 101)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 71)May include surrounding context.

rm ~/.config/systemd/user/openclaw-watchdog.service

Both

rm -rf ~/.openclaw/watchdog

text

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/setup.sh (reported line 147)May include surrounding context.

sh
chctl load "$PLIST"
    info "LaunchAgent loaded"

else
    # Linux systemd user service — write via printf (no heredoc interpolation)
    SERVICE_DIR="$HOME/.config/systemd/user"
    SERVICE_FILE="$SERVICE_DIR/openclaw-watchdog.service"
    info "Installing systemd service → $SERVICE_FILE"
    mkdir -p "$SERVICE_DIR"
    printf '[Unit]\nDescription=OpenClaw Watch Dog\nAfter=network.target\n\n[Service]\nType=simple\nExecStart=%s %s\nRestart=always\nRestartSec=10\nEnvironment=PATH=/usr/local/bin:/usr/bin:/bin\nEnvironment=OPENCLAW_HEALTH_URL=%s\n\n[Install]\nWantedBy=default.target\n' \
        "$PYTHON_BIN" "$WATCHDOG_PY" "$HEALTH_URL" > "$SERVICE_FILE"

    systemctl --user daemon-reload
    systemctl --user enable openclaw-watchdog
    systemctl --user restart openclaw-watchdog
    info "systemd service started"
fi

# ---------------------------------------------------------------------------
# 6. Verify
# --------------------------------------------------------------------------

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares installation, persistence, shell execution, environment-variable handling, file operations, and external network use, but does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens reviewability and increases the chance an agent invokes sensitive capabilities without clear consent boundaries, especially given the skill installs a background service and handles secrets.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill is explicitly designed to run as a background monitoring service, creating user-level persistence on the host. Persistence is expected for a watchdog, but it remains security-sensitive because it maintains ongoing execution, stores credentials locally, and may survive beyond the initiating session.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
**Description:** Self-healing monitoring system for OpenClaw gateway. Monitors health, auto-restarts on failure, and sends Telegram alerts. Diagnostics and log analysis run locally on-device. Alert notifications are sent to the user's Telegram bot. Use when user wants to set up gateway monitoring, watchdog, or auto-recovery.

## Prerequisites
- **Telegram Bot Token** — Create via [@BotFather](https://t.me/BotFather)
- **Telegram Chat ID** — Your personal chat ID for receiving alerts
- **Python 3** — Required for the watchdog service
- **OpenClaw** — Installed and running

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad trigger keywords like 'monitoring', 'auto-fix', and 'watch dog' can cause ambiguous or accidental activation outside a narrow intended context. Because this skill can install a persistent service and solicit credentials, overbroad routing increases the risk of unintended invocation and privilege use.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
openclaw-watchdog/references/troubleshooting.md:71

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
openclaw-watchdog/SKILL.md:101

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/troubleshooting.md:71

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:102