Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill documentation declares no permissions, yet the analyzed capability set includes environment access, file read/write, shell, and network. That mismatch is dangerous because users and orchestrators may authorize or run the skill under false assumptions, enabling unintended access to local secrets, filesystem contents, or remote endpoints.
