Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to invoke a shell script and read local configuration from ~/.openclaw/openclaw.json, but it does not declare corresponding permissions. This creates a trust and review gap: users or the platform may not realize the skill can execute shell commands and access local files containing Feishu credentials, increasing the risk of unintended secret exposure or command execution in agent contexts.
