Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation declares a simple offline PCA workflow, yet static analysis detected capabilities for environment access, file read/write, shell, and network without any declared permissions or user-facing disclosure. This is dangerous because it expands the trust boundary silently: users may run the skill believing it only performs local numeric processing while it can access credentials, invoke commands, or communicate externally.
