Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill includes documented network-capable actions (`clawdhub install` and `git clone`) but does not declare permissions or a constrained trust model for when network access is allowed. Even though these actions are framed as optional and user-initiated, undeclared network capability increases supply-chain and exfiltration risk because operators may invoke remote installs from within a skill workflow without an explicit permission boundary.
