Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill exercises sensitive capabilities including shell execution, network access, environment-variable access, and file writes, yet declares no permissions. This undermines least-privilege controls and informed review because operators may enable the skill without realizing it can call external APIs, access secrets such as API keys, and write media files locally.
