Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly states that backups include `.env` files and API keys, but it provides no warning or controls for encrypting, restricting access to, or safely storing the resulting archive. A full-system backup containing secrets materially increases exposure because anyone who obtains the archive can recover credentials, configuration, and potentially privileged access to the OpenClaw environment.
