Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill declares no permissions, yet its documented workflow requires network access, shell execution, file read/write, environment access, and local state management via a bundled Python client. This is dangerous because users and reviewers are not given an accurate permission boundary, making sensitive operations like credential storage, uploads, and local modifications less visible and less consent-driven.
