Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documents use of environment variables and file writes (`GEMINI_API_KEY`, `--output`, and `--auto-save`) but declares no corresponding permissions. That mismatch can cause the agent to perform sensitive actions without explicit user-visible authorization boundaries, especially when writing into fixed locations like `~/clawd/ad-ready/configs/Brands/`.
