Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill exercises file read, shell, and network capabilities but does not declare them, preventing users or policy layers from understanding its true privilege requirements. This weakens informed consent and makes it easier for the skill to perform impactful actions such as reading local config, invoking shells, and contacting remote services without clear disclosure.
