Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises shell execution plus file read/write behavior in its usage examples and workflow, but declares no permissions. That mismatch is a real security issue because users and enforcement systems cannot accurately assess or constrain what the skill can do before running it. In this context, the automation interacts with a logged-in shopping session and writes intermediate files, so undeclared capabilities increase the risk of unintended local actions, data exposure, or misuse of an authenticated browser state.
