Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The script writes live OAuth access and refresh tokens to predictable files under /tmp/openclaw, including a payload file later consumed by the apply step. Temporary directories are a high-risk location for sensitive credentials because other local processes/users may read, race, or retain them longer than intended, especially when no explicit permission hardening or cleanup is performed.
