Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation advertises shell execution, dependency installation, network access, and file output, but it declares no permissions. That creates a transparency and policy-enforcement gap: a user or platform may approve the skill expecting documentation-only behavior while the skill can read/write files, access environment data, and make outbound requests. In an agent ecosystem, undeclared capabilities materially increase risk because they bypass informed consent and make abuse or accidental overreach harder to detect.
