Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The scanner reads OPENCLAW_CONFIG from the environment and captures the host name, which expands its data sources beyond the advertised local config-file analysis. This is not remote code execution, but it is a genuine side-effect/privacy and trust-boundary issue because environment variables can redirect analysis to unexpected files and hostname collection adds host metadata to the output.
