Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation indicates use of environment variables for API keys and network access to third-party STT/TTS services and the OpenClaw gateway, but the manifest declares no corresponding permissions in `metadata.openclaw.requires.env`. This creates a transparency and consent problem: users and policy engines cannot accurately assess what sensitive resources the skill needs, increasing the chance of unintended secret exposure or network data transfer.
