Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions, yet its documented behavior includes reading cron data from disk, writing/deploying files, and fetching remote HTML over the network. This is a real security issue because it hides the skill's effective trust boundary from users and reviewers, making informed consent and sandboxing difficult.
