Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The collector reads agent session data, billing vault data, and OpenClaw runtime configuration from root-scoped local files, which exceeds the minimum data needed for a simple usage exporter and creates unnecessary access to broader runtime state. Even though the code appears aimed at billing/telemetry rather than overt exfiltration, aggregating sensitive local state and publishing derived results to web-served files increases exposure if the component is repurposed, misconfigured, or compromised.
