Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and demonstrates filesystem access, environment-variable expansion, report generation, and browser/report launching, but it does not declare corresponding permissions or constraints. This creates a mismatch between what the host may expect and what the skill can actually do, reducing transparency and making destructive behavior harder to govern or sandbox.
