Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation declares no permissions, yet the detected capabilities include shell, file read/write, environment access, network, and broader code execution behavior. This creates a transparency and trust failure: users may invoke the skill expecting an offline local analysis tool while it can access sensitive local resources or external services, increasing the chance of unintended data exposure or unsafe execution in agent environments.
