Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises and operationally depends on sensitive capabilities including environment access, file read/write, network access, and shell execution, yet it does not declare permissions explicitly. This weakens user and platform visibility into what the skill can do, making it easier to over-trust a skill that can handle OAuth secrets, tokens, cached vehicle data, and invoke remote vehicle-control workflows.
