Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises a narrow council/voting function, but its documented use of local model endpoints and references to external files/components imply network and file-read capabilities without any declared permissions. That hidden capability expansion weakens review boundaries and can enable unvetted data access or interaction with other local services.
