Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises offline/local processing and does not declare permissions, yet the detected capabilities include file read/write, shell, environment access, and network. This mismatch is dangerous because users and orchestrators may grant or assume a lower trust level than the implementation actually requires, enabling unintended access to local data or command execution if the underlying script is invoked.
