Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation describes use of shell commands and remote API access, but there is no declared permissions model to inform or constrain those capabilities. In a skill that handles device identifiers, JWT tokens, and household monitoring data, undeclared network and shell capability weakens transparency and can enable unintended execution paths or data exposure.
