Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises substantial capabilities that imply shell/environment access and local file handling, yet it declares no explicit permissions. This creates a transparency and consent problem: a caller may invoke a seemingly harmless data-query skill without realizing it can persist credentials locally and run host-level actions. In a skill that handles authentication tokens and account-linked business data, undeclared capabilities materially increase risk.
