Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The documentation instructs users to connect OpenClaw to remote CDP endpoints, including a third-party browserless service, without warning that browser automation traffic may expose page contents, session cookies, credentials, screenshots, and browsing context to the remote endpoint provider or any intermediary. CDP provides powerful browser control, so using remote or cloud endpoints without clear trust, transport security, and secret-handling guidance can lead to privacy leakage and account compromise.
