Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The helper reads secrets and configuration from user-level files outside the skill directory, including ~/.openclaw/.env and ~/.clawdbot/clawdbot.json, to source API credentials. That broad secret discovery exceeds the narrow search function described for the skill and creates unnecessary access to unrelated local data that could later be transmitted to external services by other parts of the skill.
