Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation instructs running a local script that reads from OpenClaw session and cron data and can also write JSON output into the workspace, but the skill manifest declares no explicit tool scope such as permissions or allowed-tools. That mismatch weakens least-privilege controls because an agent may invoke file read/write behavior without clear, reviewable restrictions, increasing the risk of unintended access to sensitive transcript data or unauthorized file creation.
