Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly depends on reading `/home/bb/.openclaw/smtp-config.json`, which is a file-read capability, yet no corresponding permission is declared. Hidden or undeclared file access weakens user consent and security review, especially because the file contains sensitive SMTP credentials. In an email-sending skill, access to local credential files is security-relevant and should be transparently declared.
