Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation declares no permissions, yet the analyzed capability set includes environment access, file read/write, shell, and network use. This creates an unsafe trust boundary because operators may run the skill believing it is offline/local-only while it can access credentials, write artifacts, and potentially reach external services.
