Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- This is a significant trust-boundary mismatch: the skill promises sandbox-only analysis and guided creation/optimization, but the finding says it actually reads real workspace files from ~/.openclaw/workspace and performs much less analysis than claimed. Users may expose sensitive configuration, prompts, secrets, or personal data under false assumptions about isolation and scope, which is dangerous even without direct file modification.
