Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions, yet the documentation clearly instructs use of environment variables, shell commands, network downloads, filesystem modification, hook installation, and cron/job setup. This mismatch is security-relevant because it can cause the harness or reviewer to underestimate the skill’s effective capabilities and trust boundary. In context, the suite is explicitly a security-management installer, so the behavior is likely intentional rather than malicious, but the undeclared capability surface is still a real issue.
