Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates capabilities to read workspace files, write reports, invoke shell commands via the OpenClaw CLI, and access an external network API, but it does not declare any permissions. This creates a transparency and policy-enforcement gap: users or the platform may treat the skill as lower risk than it actually is, and the combination of shell, file write, and network access increases the blast radius if the underlying scripts are misused or compromised.
