Intent-Code Divergence
Low
- Confidence
- 86% confidence
- Finding
- The document makes an absolute assurance that traffic goes only to a 'local webhook,' but elsewhere it clearly supports arbitrary OpenClaw Gateway destinations including Docker, Kubernetes, and cloud VPS deployments. Misleading security documentation can cause operators to underestimate egress exposure and trust remote webhook targets without proper validation, increasing the risk of unintended data disclosure.
