Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill declares no permissions, yet its instructions require environment access and MCP-backed operations, including authorization state checks and shared-file handling. This under-declaration is dangerous because reviewers, policy engines, or users may treat the skill as lower-risk than it is, allowing sensitive operations to run without appropriate scrutiny or sandboxing.
