Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation declares no permissions, yet the described execution model and referenced script imply access to shell, filesystem, environment, and potentially networked resources. This creates a trust and transparency gap: users or orchestrators may approve or sandbox the skill incorrectly, enabling broader access than expected.
