Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The skill instructs the agent to read host-level API credentials from /root/.openclaw/openclaw.json and inject them into a container environment. That creates a secret-exfiltration and privilege-boundary violation risk, because a skill framed as an experiment workflow should not independently harvest sensitive host credentials and forward them to subprocesses or external services.
