Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises install and usage steps that enable network access, shell execution, and local file writes, but it declares no permissions or trust boundaries. That gap is dangerous because users and platforms cannot make informed consent decisions, and the skill's quant-research context does not inherently require undisclosed billing/network behavior or report writing side effects.
