Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documents use of shell commands, network access, and environment variables but declares no permissions, which undermines least-privilege controls and makes the true execution surface opaque to users and reviewers. In this context, the undeclared capabilities are especially relevant because the skill can control physical hardware, access a camera stream, and run local services.
