Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation clearly describes capabilities requiring shell execution, network access, and file read/write, but it does not declare permissions explicitly. That weakens platform trust boundaries because a caller may invoke what appears to be a simple inspection skill while it can access external services and write local artifacts. In an agent setting, undeclared capabilities increase the chance of overbroad execution and accidental data exposure.
