Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill reads a Datamass API key directly from ~/.openclaw/config.json, which is a sensitive local credential source not disclosed in the stated tool description. Accessing local secrets expands the skill's effective privileges and can surprise users or upstream orchestrators that expect only TTS operations, creating unnecessary secret exposure risk if the skill is reused, modified, or logs/errors leak credential-related details.
