Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises simple local text transformations, yet the documentation indicates capabilities to read environment variables, read/write .env, and access the network without declaring corresponding permissions. This hidden capability expansion is dangerous because it can enable credential collection and outbound data transfer under a misleadingly low-risk description.
