Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill declares no permissions while instructing the agent to run Python scripts, invoke the OpenClaw CLI, access local cache files, and make network requests to COROS endpoints. This is a real security issue because the operator and any policy engine are not given an accurate view of the skill's capabilities, reducing informed consent and weakening permission-based controls.
