Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation describes shell execution, TCP connectivity to a local SBS feed, and persistence to a JSON state file, yet no permissions are declared. That creates an authorization and review gap: operators may approve or run the skill without understanding that it can read/write local files, open network connections, and invoke commands, which increases the chance of unintended access or misuse.
