Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill claims public users are restricted, but the provided bridge actually sends public messages to the same OpenClaw agent and only prepends a natural-language instruction. That is not an enforcement boundary: prompt injection or normal tool-using behavior could still cause the agent to access broader capabilities or persistent memory on behalf of untrusted senders.
