Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares itself as offline and lists no permissions, yet the detected capabilities include file access, shell execution, environment access, and network use. This creates an unsafe trust boundary: operators may approve or run the skill under the assumption that it is low-risk, while it may access local data, secrets, or external endpoints beyond what the manifest suggests.
