Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill metadata declares no permissions, yet static analysis detected capabilities for environment access, file writing, network use, and shell execution. For a market-tracking skill, undisclosed shell and file-write capability materially expand the attack surface because the skill could fetch and execute arbitrary content, access local data, or persist artifacts without user awareness.
