Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares an offline, local ETL workflow, yet static analysis detected capabilities for environment access, file read/write, network, and shell without any explicit permission declaration. That gap reduces transparency and can hide risky behavior from users, especially because config-driven pipelines and file inputs can be extended to touch sensitive local data or invoke external resources unexpectedly.
