Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill exposes meaningful capabilities beyond what is declared: it reads and writes local files, opens network connections to Redis, and documents outbound HTTP webhook transmission. Undeclared capabilities reduce informed consent and make it easier to deploy functionality that can persist state or exfiltrate message contents without operators realizing the full risk surface.
