Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The manifest/metadata is inconsistent about permissions: one section declares fileSystem and network, while the static finding indicates the skill exercises broader capabilities including shell, environment access, file read/write, and network operations. Undeclared or under-declared capabilities are dangerous because they prevent informed consent and can let a seemingly simple TTS skill execute commands, alter local state, download models, and interact with external services unexpectedly.
