Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises use of powerful capabilities (`read`, `write`, `exec`, `sessions_spawn`) but does not declare permissions in the manifest. That creates a security transparency and governance gap: operators, scanners, or policy engines may not correctly understand the skill's effective privileges, increasing the chance of unintended autonomous file or shell actions.
