Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill metadata declares no permissions, yet static analysis detected capabilities for environment access, file writing, network access, and shell execution. That combination materially expands the attack surface because users and hosting platforms cannot accurately assess what the skill may do, and a crypto-themed skill is a plausible lure for data exfiltration or command execution.
