Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The manifest advertises no declared permissions while describing installation scripts, plugin hooks, local file manipulation, shell execution, and network-linked components. This creates a transparency and consent problem: users may install a skill believing it is low-privilege when it can read/write local state, modify OpenClaw configuration, and execute commands.
