Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to request the user's PPQ API key and later persist it into the OpenClaw plugin configuration. Storing a live credential in local config without warning about sensitivity, storage location, access controls, or safer alternatives increases the risk of credential exposure through filesystem access, logs, backups, or support bundle collection.
