Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no explicit permissions, yet the manifest instructs use of shell execution, local file read/write, environment-backed identity handling, and network access. This is dangerous because it obscures the real capability surface from reviewers and users, making it easier for the skill to access local data and remote services without clear consent or policy enforcement.
