Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to use shell commands and make network connections on the local network, but the metadata declares no permissions. This creates a permission-model mismatch: a host system or user may believe the skill is low-privilege while it can actually discover devices, send control commands, and query status over LAN.
