Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly requires and instructs use of both shell and network capabilities, yet no corresponding permissions are declared. That creates a transparency and governance gap: a user or orchestrator may invoke a skill that can reach internal network services and run local commands without clear consent boundaries. In this context, the capability is expected for UniFi monitoring, but it still expands attack surface because the skill handles local gateway credentials and can access sensitive network telemetry.
