Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The onboarding flow explicitly states that the skill will obtain an API key from a remote service and save credentials under ~/.openclaw/credentials/moltguard/, but it does not warn the user before this happens. Silent credential acquisition and local secret storage can surprise users, weaken informed consent, and increase the chance that those credentials are mishandled, backed up insecurely, or exposed on a shared system.
