Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and references multiple helper scripts with network, shell, file-read, and file-write capabilities, but it does not declare any permissions or capability boundaries. That mismatch can cause an execution environment or reviewer to underestimate the skill's actual access, increasing the risk of unintended file modification, command execution, or external data exfiltration if the scripts are invoked.
