Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to use shell commands and to read/write callback state under ~/.openclaw, but it declares no permissions. That mismatch can cause the runtime or user to underestimate the skill's access to environment variables, filesystem state, and command execution, which is risky because the documented operations include modifying persistent ledgers and invoking local scripts.
