Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill instructs the agent to inspect installed skills, auto-detect directories, invoke a local Python tool, read reports, and optionally use the `clawhub` CLI for version checks, which implies file, environment, shell, and potentially network access. However, the skill declares no permissions or trust boundaries, so users and the runtime cannot accurately reason about what access is required or constrain it appropriately.
