Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The documented watcher does more than poll for notifications: it sends an authenticated POST to a local OpenClaw agent hook, which can wake or trigger downstream agent behavior based on remote server-controlled events. That expands the trust boundary from passive notification retrieval to local agent orchestration, and if the remote notification source is compromised or abused, it could cause unintended local actions or agent wakeups.
