Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation clearly instructs users to use shell commands, write to local files such as ~/.bashrc and config locations, access environment variables, and communicate with external services including Strava and Telegram, yet no permissions are declared. That creates a transparency and least-privilege problem because users and systems cannot accurately assess the skill's operational scope before enabling it.
