Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation advertises executable capabilities including shell commands, file reads/writes, and network access, but the skill declares no permissions. This creates a real security gap because users and the host platform are not given an explicit trust boundary for actions like installing packages, downloading models, modifying config.json, or making online TTS requests to Microsoft services.
