Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions, yet the described/runtime capabilities include environment access, file read/write, shell, and network use. This creates a dangerous trust gap: users and orchestrators may approve or sandbox the skill incorrectly, while the skill can still access local data, execute commands, or make outbound requests if the underlying implementation allows it.
