Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The skill is described as a watchdog that alerts and auto-restarts QClaw, but the code also exposes a remote command interface over Feishu and sends routine status messages. Expanding from alerting into remote control increases attack surface and creates capability mismatch, especially if any inbound message from the chat channel can trigger operational actions.
