Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises no declared permissions, yet the associated capability profile indicates access to environment variables, filesystem read/write, shell execution, and network. That gap prevents users and reviewers from understanding the true attack surface and can enable unintended data access or outbound communication if the skill is run in a permissive environment.
