Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions, yet its documented behavior requires reading local files, writing artifacts under the OpenClaw home directory, and invoking Python scripts via the shell. This creates a trust and review gap: operators may authorize or run the skill without understanding that it can access the filesystem and execute commands, which increases the chance of unintended file exposure or unsafe command execution in the broader agent environment.
