Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises a document-analysis workflow but declares no permissions while its behavior implies broad capabilities including shell, file I/O, network access, and environment access. This is dangerous because users and policy engines cannot accurately assess or constrain what the skill can do, increasing the risk of unintended file access, command execution, or external data exfiltration during processing.
