Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill instructs the agent to inspect environment/plugin state via OpenClaw commands and referenced scripts, but the metadata shown does not declare corresponding permissions. Undeclared capabilities make review and containment harder and can lead to unexpected execution paths or access to local environment details during normal use.
