Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs users to run shell scripts that read notifications and write exported data into the OpenClaw memory tree, yet the skill metadata declares no permissions. This is dangerous because operators and policy engines cannot accurately assess or constrain the skill's access to local data and shell execution, especially given that notification contents often contain sensitive work and personal information.
