Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill declares no permissions while its instructions clearly require shell execution, filesystem access, network communication, environment use, and local state changes. This is dangerous because it hides the true privilege and attack surface of the package, preventing informed consent and making abuse or unintended side effects harder to detect.
