Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises and documents shell, file read/write, environment, and likely broader execution capabilities without declaring permissions or constraining them in the manifest. This creates a transparency and governance gap: consumers may invoke a skill that can access local Contacts data and mutate local state without an explicit permission boundary, increasing the risk of unintended data exposure or modification.
