Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises and documents shell execution, file reads/writes, backup/restore of system and workspace data, and cloud/NAS upload scenarios, but no explicit permissions are declared. That creates a trust and policy-bypass risk: an agent or reviewer may treat the skill as low-privilege while it can invoke powerful filesystem and shell operations on sensitive OpenClaw data.
