Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read environment variables, install and run a CLI, modify `~/.openclaw/openclaw.json`, restart the gateway, and interact with an external API hub, which clearly exercises env, file read/write, and network capabilities. Because no permissions are declared, users and the platform lack an explicit consent boundary for sensitive actions such as accessing `SKILLBOSS_API_KEY` and changing persistent configuration, increasing the chance of silent or unexpected privileged operations.
