Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises significant capabilities—environment access, file read/write, shell, and network use—without declaring permissions or prominently warning users. That makes consent and review harder, and in practice it can enable unexpected outbound communications, local persistence, and command execution under the guise of a simple timer utility.
