Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation indicates access to environment data and local file writes, including persistent state under ~/.clawdbot/linkedin-monitor/, but does not declare corresponding permissions. Undeclared capabilities weaken user consent and sandboxing assumptions, especially for a skill that handles messaging workflows and may process sensitive account state.
