Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises a network-backed script (`scripts/train_query.py`) and the static analyzer detected file-write and network capabilities, but the manifest does not declare any permissions. Undeclared capabilities are dangerous because they hide the skill's actual trust boundary from reviewers and users, making it easier for a skill to perform unexpected outbound requests or local file modifications without informed consent.
