Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to invoke an external CLI (`openclaw directory groups list --channel discord --json`) even though the skill’s operating principle says verification should use OpenClaw-native tools. This expands the trust boundary and can expose the agent to unreviewed local command execution behavior, inconsistent authorization controls, or unintended data access beyond the managed tool layer.
