Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exposes shell execution and workspace read/write behavior through documented commands, but declares no permissions to inform the host or user of those capabilities. This creates a security transparency gap: users may invoke a skill that can modify files and inspect workspace contents without an explicit permission declaration, increasing the chance of unintended or unsafe use.
