Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The server exposes a generic run_agent interface that forwards arbitrary caller-supplied messages to the local OpenClaw agent, which is effectively a powerful command/delegation primitive. In the context of a voice-assistant integration, this materially expands the attack surface because any party with the bearer token can cause broad agent actions beyond narrowly scoped assistant tasks.
