Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises operational steps that invoke shell commands (`python -m pip install -e .`, `openclaw mcp set ...`, `pytest`) and interacts with local files and environment variables, but it does not declare any permissions or capability boundaries. This creates a trust and consent gap: an agent or reviewer may treat the skill as low-risk documentation while it actually enables package installation, local server registration, file writes, and environment-dependent execution on the host.
