Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no permissions, yet its own instructions require shell execution, network access, environment-variable access, and file writes via environment bootstrapping and virtualenv/package installation. This hidden capability expansion weakens platform trust boundaries and can lead users or orchestrators to approve a skill as low-risk when it can actually execute code, modify the host environment, and access cloud credentials.
