Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill declares no permissions, yet the documented and detected capabilities include shell, network, environment access, and file read/write. This creates a transparency and least-privilege problem: users and orchestration systems may trust the skill as local-only while it can access sensitive resources or external services. In this context, the mismatch is more dangerous because the privacy section explicitly claims offline/local processing, which can mislead users about actual exposure.
