Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill declares no permissions, yet the analyzed capabilities indicate access to environment variables, filesystem I/O, shell execution, and network. That mismatch prevents users and policy engines from making informed trust decisions and can hide unexpectedly powerful behavior, especially in an agent ecosystem where skills may be auto-invoked.
