Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation declares no permissions, yet the detected capabilities include environment access, file read/write, shell, and network. This creates a transparency and least-privilege problem: users and orchestrators may authorize or run the skill under a false assumption that it is offline and low-risk, while the implementation can access secrets, modify files, and reach external services.
