Context-Inappropriate Capability
High
- Confidence
- 96% confidence
- Finding
- The installer writes an OpenClaw extension that exposes multiple local tools which invoke a locally installed binary via shell command construction. Several commands interpolate user-controlled fields into a string passed to execSync, and escaping is incomplete, creating command-injection risk and granting the skill persistent local code-execution capability beyond what the description clearly warns about.
