Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The documentation instructs reading `appId` and `appSecret` directly from a local OpenClaw config file in the user's home directory. That encourages the skill to access unrelated local secrets outside normal explicit user provisioning, which expands its scope from voice processing into credential harvesting and could expose Feishu bot credentials to logs, subprocesses, or other components.
