Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill documentation advertises shell execution, environment-variable use, and network access (model download and mirror configuration), yet no permissions are declared. This creates a transparency and policy-enforcement gap: users or orchestrators may invoke a skill believing it is low-privilege when it can actually reach the network and execute setup/runtime commands.
