Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The documentation tells users credentials live in ~/.openclaw/secrets/mail_qq.env, but the example code actually defaults to a hard-coded Windows Administrator path. This mismatch can cause the skill to read credentials from an unintended location, potentially another account’s secret store on shared or misconfigured systems, and breaks operator expectations about where sensitive data is sourced.
