Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions, yet its own instructions explicitly require shell execution, outbound network access, environment-variable reads, and access to bundled local files. This mismatch weakens sandboxing and review guarantees because the runtime may permit more capability than the manifest communicates, making operator trust and policy enforcement less reliable.
