Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read and write local OpenClaw configuration and execute shell commands, but it does not declare corresponding permissions. That creates a capability/permission mismatch: users and the platform cannot clearly see that invoking this skill can modify local state, restart services, and persist credentials. In this context the risk is elevated because the workflow writes Feishu secrets into local config and can restart the gateway.
