Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to execute networked scripts and update local files, but the manifest shown does not declare corresponding permissions. That mismatch can undermine permission gating and user/operator expectations, especially for a skill that fetches remote content and writes cached artifacts. In this context the behavior appears functionally intended, but undeclared capabilities increase the chance of silent overreach rather than reflecting a harmless documentation issue.
