Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill declares no permissions while instructing use of a bundled Python client that performs shell execution, file access, network calls, local credential handling, and package mutation. That mismatch removes an important trust boundary for users and hosts, making the skill more dangerous because broad capabilities are present without explicit disclosure or least-privilege scoping.
