Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill reads Feishu credentials from environment variables, a global OpenClaw config, and local config.json, which expands its privilege scope beyond basic Git monitoring into credential access. Even if intended for notifications, this undisclosed access to unrelated secrets increases the blast radius of the skill and creates unnecessary secret exposure opportunities.
