Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 76% confidence
- Finding
- The skill declares no permissions, yet the detected capabilities include network, shell, file access, and environment access. This is dangerous because users and orchestrators cannot accurately assess the skill’s operational reach, and hidden capabilities can enable unintended data access, command execution, or external communications beyond the stated offline geospatial purpose.
