Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares restrictive permissions (`network: false`, `shell: false`) but the content explicitly instructs users to open external URLs, install additional packages, and download a separate ZIP containing an 'unlocked autonomous agent stack'. Even though this file is documentation rather than executable code, it functions as an onramp to undeclared network and shell activity and could mislead operators or downstream tooling that relies on the manifest's permission claims.
