Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation directs use of file I/O, network ingestion, and shell-backed scripts (for cron setup, persistence, and content fetching) but does not declare corresponding permissions. This creates a permission-model mismatch where reviewers or runtime policy may underestimate the skill’s actual capabilities, increasing the risk of unauthorized filesystem changes, scheduled task creation, or external data access.
