Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises significant effective capabilities (environment access, file read/write, network, and shell) but does not declare permissions or provide corresponding trust boundaries in the manifest/documentation. That creates a transparency and governance gap: hosts may invoke the skill without understanding that it can store credentials locally, make outbound requests, and execute local commands, increasing the chance of over-privileged deployment and unsafe integration.
