Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation describes capabilities that read/write local files and execute shell scripts, but it does not declare any permissions or capability requirements. This creates a transparency and consent problem: users or host platforms may invoke the skill without understanding that it will create files, start a server, and run local commands. In this context the behavior appears aligned with the skill's stated purpose, so the issue is under-declaration rather than overtly malicious behavior.
