Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises and documents capabilities that involve shell execution, network access, and environment/file access, but it does not declare corresponding permissions. This creates a trust and review gap: users may install it expecting a UI-only chat manager while it can invoke CLI commands and access local OpenClaw data.
