Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to execute local Python scripts, use network access for weather and webhook delivery, read environment variables and local OpenClaw config, and maintain per-chat selection state, yet it declares no permissions. This creates a dangerous transparency and consent gap: operators and policy engines may treat the skill as low-privilege while it can access secrets, local files, and external endpoints.
