Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares itself as an offline/local terrain renderer, yet the detected capabilities include network, shell, environment access, and unrestricted file read/write without corresponding permission disclosure. That gap is dangerous because it prevents users and reviewers from understanding the real attack surface, and those capabilities could be used to access local data, invoke external tools, or contact remote services unexpectedly.
