Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes a Python script, tails OpenClaw logs, and optionally writes JSON output, which implies shell execution plus file read/write capability, yet the manifest does not declare any tool scope or permissions boundary. This creates an avoidable trust gap: callers and policy systems cannot easily determine or restrict what the skill is allowed to do, increasing the chance of over-privileged execution or misuse if the implementation changes or is repurposed.
