Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The installer reads an existing Anthropic API key from OpenClaw auth storage and reuses it automatically. While this may be intended as convenience for setup, it expands the skill's capability into credential access, which is more sensitive than simple model routing and creates risk if the script or routed service is compromised.
