Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation describes capabilities to read/write local configuration files, execute shell commands, and make network requests, but it does not declare any permissions or constraints for those actions. This creates a trust and transparency gap: an agent or reviewer cannot easily understand the skill's operational scope, and the combination of filesystem, shell, and network access increases the blast radius if the skill is misused or implemented unsafely.
