Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill claims to be only a thin interaction/notification router with per-user data isolation, but the described behavior includes host-level cron management, local state storage under ~/.openclaw, workspace .env loading, and additional profile/history/cancellation flows. That mismatch is dangerous because operators and users may trust the skill with a lower-risk model than it actually has, leading to underestimation of local data exposure, token handling, and persistence on the host.
