Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly states that it scans local session history files under ~/.openclaw/agents/main/sessions/*.jsonl, which may contain sensitive conversation content and metadata. Even if only token counts are intended, reading historical local session data without a clear privacy warning, minimization statement, or consent boundary creates a real privacy risk if users are unaware their conversation history is being processed.
