Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes local code and uses environment variables plus file reads/writes, but it does not declare those capabilities or obtain explicit user consent. Hidden capability use is dangerous because users and the hosting platform cannot accurately assess what the skill will access or modify, especially when it writes persistent data under the user's home/config directory.
