Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation shows capabilities to read and write local files, access the network, and invoke shell commands, but it declares no permissions. That creates a transparency and consent problem: users and any permission-gating system cannot accurately assess what the skill will do before installation or execution.
