Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions, yet the documented/runtime capabilities include file access, shell execution, environment access, and network use. This is dangerous because users and orchestrators may trust the skill to be offline and low-privilege, while the actual implementation could access local data or external services without informed consent.
