Context-Inappropriate Capability
Medium
- Confidence
- 86% confidence
- Finding
- The server reads Oris credentials from a local OpenClaw config file when environment variables are absent, which expands its credential access scope beyond what a payment tool strictly needs at runtime. In an agent-skill context, implicit local file credential discovery is risky because it enables unattended use of stored secrets without an explicit user consent step or clear disclosure.
