Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation describes capabilities to read secrets from environment variables or ~/.openclaw/.env and send authenticated requests over the network, but no explicit permissions are declared. This creates a real security gap because users and policy systems are not informed that the skill can access credentials and exfiltrate them to a remote endpoint, even if the intended purpose is legitimate web search through a self-hosted proxy.
