Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises and instructs use of filesystem, environment, and shell-capable operations, but it does not declare permissions or an equivalent trust boundary in the skill metadata. That creates a transparency and governance gap: a reviewer or runtime may underestimate the skill's ability to read sensitive files, inspect ~/.openclaw, invoke CLI commands, and potentially modify local state when users run fix/apply modes.
