Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions despite requiring environment access, file read/write, network access, and shell execution. This hides the true trust boundary from the user and platform, making sensitive actions like reading profile data, persisting logs, and invoking external commands harder to review and control.
