Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no required permissions, yet its documented behavior clearly includes network access, shell command execution, environment-variable secret handling, and reading/writing local files such as .cache. This permission mismatch is dangerous because it obscures the skill's real capabilities from the host/user, reducing informed consent and weakening policy enforcement around secrets, filesystem access, and external API calls.
