Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs use of shell commands, environment-backed secrets, local files, curl, and a long-running WebSocket client, but the metadata declares no corresponding permissions or trust boundaries. This under-declaration can mislead users and host systems into granting execution/network capabilities without clear consent, increasing the chance of unsafe deployment.
