Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The script persists sensitive Asana credentials to predictable plaintext files under ~/.openclaw/asana using default filesystem permissions and without any warning or hardening. On multi-user systems, shared environments, backups, or compromised local accounts, these stored PAT/OAuth tokens could be recovered and then used to read or modify Asana data remotely.
