Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises significant capabilities including environment access, file reads/writes, network access, and shell execution without declaring permissions or presenting a least-privilege boundary. That makes it easier for operators and users to underestimate what the skill can access, and it increases the chance of unintended credential, file, or command execution exposure.
