Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes local scripts that read and write files under /tmp and can make live outbound network requests to ElevenLabs, yet the skill metadata declares no permissions. This creates a capability/permission mismatch that can bypass operator expectations and policy enforcement, increasing the chance the skill is run with more access than reviewers realize.
