Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill declares no explicit permissions even though it clearly uses shell execution, environment overrides, and multiple network channels. This is dangerous because reviewers and users are not given an accurate capability boundary, which can cause them to approve a skill that can transmit data, execute commands, and alter runtime behavior beyond what the manifest suggests.
