Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill manifest presents a lightweight interpretation skill, but the package appears to exercise file, network, shell, and write capabilities without declaring them. Undeclared capabilities are dangerous because they prevent accurate risk assessment and sandboxing, and they can expose local audio, enrollment data, or fetched model assets to unintended handling paths.
