Competitor Intel

OpenClaw: attach --print-config Can Print a Live MCP Token Without a Log-Safe Mode

attach --print-config can print a live MCP token. A troubleshooting command can therefore copy a credential into terminal history, logs, tickets, or support evidence.

📋 Issue Summary

attach --print-config can print a live MCP token. A troubleshooting command can therefore copy a credential into terminal history, logs, tickets, or support evidence.

Diagnostic Output Can Leak Credentials

attach --print-config can print a live MCP token. A troubleshooting command can therefore copy a credential into terminal history, logs, tickets, or support evidence.

No Log-Safe Mode

Without default redaction or a log-safe output option, operators must remember to protect a diagnostic stream at exactly the moment they are investigating an incident.

Secrets Must Be Redacted by Default

Configuration tooling should mask secrets by default and require deliberate, audited reveal behavior when an operator genuinely needs a value.

Operational Security Beyond Storage

Credential protection depends on safe runtime diagnostics as well as encrypted storage. Logging and support workflows must not become the leak path.

⚠️ Critical Assessment

P1 — A diagnostic command can print a live MCP token without a log-safe mode, creating a concrete credential-exposure risk in terminals, logs, and support artifacts.

🔗 Sources

Methodology & Sources

This analysis is based on publicly available documentation, community forums (Reddit, Discord, GitHub), vendor-published case studies, security compliance reports, and hands-on testing by the gobii.reviews editorial team. All claims are sourced and verified. We do not accept payment for inclusion or ranking. See our full methodology and editorial standards.

Last updated: June 30, 2026. Published by the gobii.reviews Editorial Team.