Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no explicit permissions, yet the content clearly instructs use of shell commands (`bash`, `curl`, `jq`) and local file access. This creates a transparency and sandboxing gap: a host may permit the skill under a lower-trust model than its actual capabilities warrant, increasing the chance of unintended command execution and secret/file access.
