Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs the agent to execute shell commands (`bash scripts/...`, `curl`, `jq`, `openclaw config`) but does not declare permissions accordingly. This creates a trust and review gap: operators may approve or run the skill without realizing it has command-execution capability and can exfiltrate local files to a remote service.
