Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read arbitrary local skill folders and execute shell commands such as `python3 .../check_publish_ready.py`, `clawhub publish`, and `clawhub search`, but it does not declare permissions for file reads or shell execution. That mismatch is a real security issue because users and platform controls may not have clear visibility that the skill can inspect local files and invoke publishing commands that interact with external services.
