Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill documentation describes runtime behavior that reads input files, writes report outputs, accesses network resources to collect WeChat articles, and invokes a shell command, yet it declares no explicit permissions or capability boundaries. This creates a mismatch between stated metadata and actual behavior, which can lead to over-privileged execution, weak reviewability, and unsafe use in environments that rely on declared permissions for policy enforcement.
