Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no explicit permissions, yet its documented behavior includes reading files, writing files, inspecting environment variables, invoking shell commands, and performing network-dependent package installation during verification. This creates a real trust and review gap: a caller may assume a narrower capability set than the skill actually uses, increasing the chance of unintended file access, config mutation, or external connectivity in sensitive environments.
