Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions even though its detected capabilities include file read/write, network access, and shell execution. That creates a serious transparency and containment problem: a user or platform may authorize an email/calendar skill expecting Microsoft Graph-only behavior while the implementation can access local files, invoke commands, and make arbitrary outbound requests.
