Context-Inappropriate Capability
Medium
- Confidence
- 84% confidence
- Finding
- The auto-notify feature instructs spawned agents to invoke a host-level `openclaw system event` command on completion. This creates a cross-boundary side effect outside the immediate coding task and gives delegated agents a mechanism to trigger host events, which can be abused for signaling, spam, or unintended orchestration behavior.
