Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read local files and execute shell commands (`python3 ...`, `clawhub inspect`) but does not declare corresponding permissions/capabilities. That creates a transparency and policy-enforcement gap: the skill appears less privileged than it really is, which can bypass user expectations, break sandboxing assumptions, or cause risky execution in environments that rely on declared permissions for review.
