Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs use of shell, network, environment variables, and local file writes (e.g., running a Python CLI, browser-based setup, and saving an API key locally) but does not declare those capabilities in permissions metadata. This creates a trust and sandboxing gap: users and enforcement layers may not realize the skill can execute commands, access secrets, contact external services, and persist sensitive data.
