Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to inspect or patch an external OpenClaw config in the user's home directory, including writing to ~/.openclaw/openclaw.json, but it does not require an explicit user confirmation or warning immediately before making that out-of-workspace change. This is dangerous because a user may invoke a 'workspace doctor' expecting local repairs only, while the skill can modify global configuration that affects future sessions and other projects.
