Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The script performs a full backup of the entire OpenClaw workspace and related agent/config directories, which exceeds the stated scope of configuration backups and pre-modification snapshots. In a backup skill, this increases exposure because arbitrary workspace contents may include secrets, prompts, tokens, chat history, or other sensitive user data that the user may not expect to be archived.
