Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill declares itself as offline and privacy-preserving, yet the detected capabilities include network, shell, environment access, and file read/write without any explicit permission disclosure. This is dangerous because users and orchestrators may grant or invoke the skill under a false trust model, enabling unintended local data access or outbound communication if the implementation uses those capabilities.
