Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to perform a direct `sqlite3` INSERT into a persistent database file under `~/.openclaw/data/bankroll.db` without any warning, confirmation step, input validation guidance, or rollback/audit safeguards. In an agent setting, this can cause unintended or user-unapproved modification of financial tracking data, and the danger is increased because the skill’s purpose is to manage bankroll and risk limits, making integrity of the stored data important.
