Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares no permissions even though its documented behavior and detected capabilities require environment access plus reading and writing local files. This undermines informed consent and review because installers cannot accurately assess that it patches installed code, maintains a local cache, and touches workspace files. In this context, the mismatch is more dangerous because the skill operates on WhatsApp message flow and persistent OpenClaw files, so hidden capabilities affect both privacy and system integrity.
