Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and instructs use of capabilities including shell execution, environment-variable use, network access, and scheduled automation, but it does not declare permissions or clearly scope those powers. This weakens reviewability and informed consent: operators may install a skill that can make outbound requests and run unattended commands without explicit permission metadata.
