Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and instructs use of shell execution, network access, and file export while declaring no permissions, which creates a transparency and consent gap for a capability set that can launch Chrome, connect to a live browser debugging port, navigate arbitrary sites, and write scraped data to disk. In the context of reusing an authenticated local browser session, these undeclared capabilities are especially sensitive because they can access account-scoped data and persist exported results without an explicit permission model or user warning at the skill boundary.
