Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly exercises sensitive capabilities including shell execution, network access, and file reads/writes, but does not declare permissions or equivalent capability disclosures in the manifest. That weakens user consent and platform enforcement because operators may not realize setup downloads software, accesses RTSP streams, stores snapshots, and sends notifications outbound.
