Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill describes operational behaviors that imply broad capabilities—reading and writing local files, optional semantic retrieval, scheduler integration, and possibly shell/network-backed host features—without any declared permission model or capability scoping. In an agent environment, this can let a seemingly advisory skill gain effective access to sensitive files and execution surfaces without transparent user consent or runtime restriction.
