Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises no explicit permissions, yet its documented operation requires shell execution, local file access, network access, credential storage, and package modification behavior. This is dangerous because users and hosts cannot make an informed trust decision when the effective capabilities are broader than the declared permission model, increasing the chance of unintended data access or command execution.
