Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs users to run shell commands that read and write files under ~/.openclaw and execute installation scripts, yet it declares no permissions. This is a real transparency and trust-boundary issue because users and hosting systems cannot accurately assess the skill's capabilities before installation.
