Missing User Warnings
Low
- Confidence
- 84% confidence
- Finding
- The README instructs users to place a live Miremo API key directly into a local OpenClaw config file, but it does not explicitly warn about risks such as accidental sharing, weak file permissions, shell history leakage during editing, or inclusion in backups and dotfile sync tools. This is not inherently malicious, but it does normalize storing long-lived credentials in plaintext and can lead to credential exposure if the local environment is compromised or the config is mishandled.
