Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The onboarding flow expands beyond configuring the Vexa skill itself and instructs the assistant to modify broader OpenClaw webhook and report-pipeline configuration. This increases blast radius by changing global integration behavior, which could affect unrelated skills or routes and create unintended data flows without clear user-scoped consent.
