Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill appears to require file reads, network serving, and shell/process control, but none of these capabilities are declared in the skill metadata. That creates a transparency and review gap: operators may approve a seemingly simple local browser tool without realizing it reads sibling skill files, exposes HTTP endpoints, and invokes shell commands. In this context, the mismatch increases risk because the tool operates over local disk content and local processes, which can affect confidentiality and system stability.
