Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares itself as offline/local and does not document any permissions, yet the analyzed capabilities include environment access, file read/write, shell, and network. This mismatch is dangerous because it expands the attack surface beyond user expectations, enabling unreviewed access to local data, execution of external commands, and possible outbound communication if the underlying implementation is invoked.
