Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents use of a bearer token in `openclaw-config/.env` and operational access to a local API, but provides no warning about secret handling, redaction, or avoiding disclosure in logs, terminal output, or published artifacts. In a skill that permits Bash/Read/Write and troubleshooting workflows, this increases the chance that an agent or user will expose credentials during routine use.
