Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The documented interaction flow says that entering a number installs a GitHub result, but it does not explicitly warn the user that this action pulls and installs code from a remote repository. That omission can lead users to execute untrusted third-party code with the authority of the OpenClaw environment, increasing supply-chain and remote code execution risk.
