Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises local-only storage and explicitly references reading and writing `~/.openclaw/workspace/memory/verifier/cases.json`, but it does not declare corresponding permissions. That mismatch can undermine platform trust boundaries and user consent by enabling filesystem access that is not transparently surfaced through the permission model.
