Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill appears to use file read and network capabilities without declaring them, which breaks the expected permission model and reduces a user's ability to make an informed trust decision. Undeclared capabilities are especially concerning in an agent skill because network and file access can enable data exfiltration, remote control paths, or unexpected interaction with local resources.
