Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill documentation instructs users to copy files into the OpenClaw workspace and run a Python script, and it also describes local log storage and configuration files. That means the skill clearly relies on file read/write behavior, but no permissions are declared, creating a transparency and policy gap that can hide filesystem access from users and reviewers.
