Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documents and encourages executable capabilities including network access, reading/writing cache files, and likely environment access, but the skill metadata does not declare any permissions. That creates a trust and governance gap: a host may approve or route the skill assuming it is low-privilege while the bundled scripts perform live API calls and write under ~/.cache, which can lead to unintended data access or persistence.
