Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill routes DingTalk user messages to the OpenClaw HTTP API and also logs message content locally, but the description does not clearly warn users or operators that conversational content is transmitted and stored. This creates a real privacy and data-handling risk because sensitive business or personal data may be exposed without informed consent or appropriate operational controls.
