Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises and relies on capabilities including environment access, local file reads, network access, and shell execution, but does not declare permissions explicitly. This weakens sandboxing and user awareness, making it easier for sensitive operations like API-key access or command execution to occur without clear policy review.
