Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read environment variables, read and write local files, invoke shell commands, and handle network URLs, but it does not declare corresponding permissions. This creates a trust and containment problem: users and the platform cannot accurately assess or constrain what the skill may do, and the broad filesystem path (`~/.openclaw/workspace/work-schedule/`) plus shell-based operations increase the blast radius if the skill is misused or implemented unsafely.
