Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs users to provide an API key that will be sent to a third-party endpoint and then modifies a local configuration file under ~/.openclaw/openclaw.json, but the documentation does not clearly warn users about these external transmission and local system changes before use. This is dangerous because users may unknowingly disclose credentials to an external service and permit persistent configuration changes that affect future agent behavior.
