Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 88% confidence
- Finding
- The skill is presented as agent memory, but its documented behavior includes broader capabilities: arbitrary file upload/download, credential setup/storage, browser-assisted auth flow, and modification of local state files such as `~/.openclaw/.env` and `MEMORY.md`. That gap can cause users or agents to invoke it under a narrower trust model than warranted, increasing the chance of unintended exfiltration of local data to permanent public storage or unwanted local state changes.
