Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill directs users to run a Python script, use Playwright, configure cron, and invoke the openclaw CLI, which implies shell execution and possible file writes, yet the skill declares no permissions. That mismatch is a real security issue because it hides the skill's operational capabilities from reviewers and users, reducing informed consent and making misuse or unintended side effects harder to assess.
