Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill metadata declares no permissions, yet the implementation reportedly has file read, network, and shell capabilities. That mismatch is dangerous because callers and reviewers cannot accurately assess what the skill may do at runtime, and shell/network access materially expands the attack surface for command execution, data exfiltration, and unreviewed external interactions.
