Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script reads the gateway authentication token from local configuration and prints it directly to the terminal. This unnecessarily exposes a live credential that may be captured in terminal scrollback, screen recordings, shared logs, or shoulder-surfing, enabling unauthorized access to the local OpenClaw gateway.
