Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no permissions, yet its instructions explicitly require shell execution, network access, environment variable use, and local file writes during environment bootstrapping. This is dangerous because a caller may treat the skill as low-risk/read-only while it can install dependencies, contact external services, and persist data locally, expanding the attack surface and enabling unintended code execution paths.
