Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises executable capabilities such as shell access, environment-variable use, and file read/write, but does not declare permissions in the manifest. This creates a transparency and governance gap: users and security tooling cannot accurately assess what the skill is allowed to do before invocation, increasing the risk of unexpected file modification or command execution.
