Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell commands and reads/writes local files (`scripts/interceptor.py`, `scripts/trust_tracker.py`, `assets/trust_db.json`) without declaring permissions. This creates hidden capability exposure: a host or reviewer may treat the skill as low-privilege while it can actually execute commands and persist state, which is especially risky because the trust database influences future security decisions.
