Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill metadata claims minimal/offline behavior, but static analysis indicates access to environment data plus network and shell-capable behavior without declaring corresponding permissions. That mismatch is dangerous because users and orchestrators may grant execution under false assumptions, enabling unexpected data exposure or command execution pathways.
