Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions while its documented behavior clearly requires environment access, file read/write, outbound network calls, and shell execution. This is dangerous because it hides the true capability surface from reviewers and users, undermining informed consent and making it easier for the skill to access credentials, write local artifacts, and transmit data externally without explicit approval.
