Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill documentation declares no permissions, yet the detected capabilities include shell, filesystem, environment access, network, and file write operations. This creates a trust and review gap: users may invoke a seemingly local/offline symbology tool without realizing it can access sensitive local data or perform external actions. The stated offline/privacy posture makes the undeclared capability set more concerning, because it could mislead users about actual execution risk.
