Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill’s stated purpose is querying market data, but it also instructs the agent to modify the user’s local OpenClaw configuration to persist credentials. That expands the skill from a read-only network client into one that performs local state changes involving secrets, which creates unnecessary risk if the key is mishandled, overwritten, or later exfiltrated.
