Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to read API credentials from a local OpenClaw configuration file and export them into the shell. That exceeds the minimum privilege needed for a map-control skill and normalizes local secret harvesting behavior, which could be repurposed to access or expose sensitive values without clear user consent.
