Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares only `network: true`, but its instructions also require reading and writing local files and using environment-backed credentials. This capability mismatch is dangerous because it hides the real trust boundary from users and policy systems, making silent file modification and credential-dependent behavior easier to trigger without clear review.
