Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation declares no permissions, yet the analyzed capability set includes file access, shell execution, environment access, and network use. This is dangerous because operators may run the skill under an incorrect trust model, exposing local files, secrets in environment variables, or external connectivity that the documentation explicitly downplays as offline/local-only.
