Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions even though it clearly performs sensitive actions: reading and writing files, invoking shell/VBScript/attrib, accessing environment/runtime context, and downloading remote SVG content. Missing permission disclosure is dangerous because users and orchestrators cannot accurately assess or sandbox the skill, increasing the chance of unexpected filesystem changes or execution of platform commands.
