Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The example states that host access is 'vollständig blockiert' / completely blocked, but the container mounts ./data into /home/openclaw/.openclaw without a read-only flag. That means the agent can still modify host-backed files in that mounted path, so the documentation overstates the isolation boundary and could lead operators to grant more trust than is warranted.
