Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The script advertises automatic removal of sensitive information, but only sanitizes openclaw.json while copying workspace files, memory, and skills verbatim. In a deployment/export tool, those directories can easily contain secrets, tokens, prompts, internal notes, or proprietary code, so users may wrongly trust the package as safe to share and unintentionally leak sensitive data.
