Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions while its documented behavior clearly involves shell execution, network access, local file handling, and likely environment usage. This mismatch is dangerous because it hides the real attack surface from users and policy enforcement, making unintended data access or outbound transmission easier to miss.
