Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation advertises network access, downloading remote content, and restoring files into the workspace, yet it declares no permissions. This creates a trust and review gap: operators may approve or run the skill without understanding that it can read/write local files and fetch attacker-controlled remote data.
