Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill metadata declares runtime requirements but does not explicitly declare permissions, while the described behavior clearly includes reading local skill files, writing a report to /tmp, making network requests to ClawHub, and accessing an environment variable for the VirusTotal API key. This mismatch is dangerous because it weakens transparency and permission review, making it easier for users or automated systems to approve a skill without understanding its actual access to local files, outbound network destinations, and sensitive environment data.
