Intent-Code Divergence
Medium
- Confidence
- 91% confidence
- Finding
- The package declares a normal web chat application, but its postinstall hook performs a filesystem side effect by copying files into ~/.openclaw/workspace/chat-web/public/. Install-time scripts execute automatically during dependency installation, so this behavior can modify a user's workspace without explicit consent and can be abused to overwrite or seed content in another application context.
