Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises shell execution and file-writing behavior without declaring permissions, which weakens any permission-based safety model and can surprise callers into granting the skill more trust than it deserves. In this context, the skill processes local files and invokes external tooling, so undeclared capabilities increase the risk of unintended file modification or command execution paths.
