Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill invokes shell commands and Python scripts that read/write local files, access credentials, and use network services, yet it declares no permissions. This weakens platform trust boundaries and informed consent because users and policy engines cannot accurately assess that the skill will touch the filesystem, use secrets, and contact external services.
