Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The script reads detailed OpenClaw configuration from /root/.openclaw/openclaw.json, including gateway port, primary model, and fallback model chain, which goes beyond basic health monitoring. In a Telegram/CLI health-check context, exposing root-owned configuration data can leak operational details to less-privileged users or remote chat recipients, aiding reconnaissance and revealing sensitive deployment metadata.
