Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill clearly instructs use of shell commands, network access, local file reads/writes, and scheduled monitoring, yet declares no permissions. This creates a misleading trust boundary: a reviewer or runtime may treat it as lower risk than it really is, while the skill can transmit data externally and persist state locally.
