Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The documented behavior materially exceeds the declared purpose: it persists session data, manages session lifecycle, reads local configuration, invokes the OpenClaw CLI, and logs configuration details. This mismatch reduces informed consent and can expose sensitive conversation content or configuration data, especially because users may install it expecting only in-memory token compaction.
