Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The callback handler forwards Feishu card callback content, including operator, action, context, and raw event data, to an external OpenClaw Gateway. This expands the data flow beyond a local card-handling function and can expose user interaction metadata or submitted form contents to another service without strong scoping, minimization, or explicit disclosure.
