Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation declares no permissions, yet the analyzed capability set includes shell, file read/write, environment access, and network access. This is dangerous because it prevents users and platforms from making informed trust decisions and can hide data access or command execution surfaces that exceed the stated offline hydrology purpose.
