Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises commands that can read and write files, access environment variables, invoke shell commands, and potentially process externally supplied threat data, but it declares no permissions in the skill metadata. That mismatch is dangerous because users and hosting platforms cannot accurately assess or constrain what the skill is capable of before invocation, increasing the chance of unsafe execution in sensitive workspaces.
