Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill describes filesystem reads, writes, and shell-based operations, but the manifest does not explicitly declare those capabilities. That mismatch weakens policy enforcement and informed consent because users and platforms cannot clearly see that the skill will scan credential files, create backups, modify .env files, and delete old files. In a credential-handling skill, hidden or implicit capabilities are more dangerous because they operate on highly sensitive material.
