Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill advertises broad management capabilities, but the documented behavior extends to reading ~/.openclaw/workspace/TOOLS.md for device definitions and potentially sensitive metadata that is not clearly disclosed in the top-level description. This hidden configuration source can expose credentials or host inventory unexpectedly, and the mismatch around REST/OLT support can mislead operators into unsafe trust assumptions about what the skill actually does.
