Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The script persistently logs sensitive user activity to ~/.openclaw/cache/tavily-search-pro-native-node/usage.log, including search queries and extracted URLs. In an agent/tooling context, queries and URLs often contain confidential research topics, internal targets, or tokens embedded in URLs, so storing them silently on disk creates a privacy and data-retention risk if the host is shared or later compromised.
