Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README advertises a "Premium remote audit" service via ACP but does not clearly disclose that using it may send OpenClaw configuration data off the local machine. Since this skill explicitly handles security audits and secret detection, users may provide highly sensitive configs containing tokens, keys, network topology, or agent permissions; omission of a transmission/privacy warning increases the risk of unintended data exposure.
