Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill advertises and operationalizes powerful capabilities including filesystem access, environment-variable use, shell execution, and network exposure, yet does not declare permissions or trust boundaries. That mismatch increases the risk of over-broad invocation and unsafe deployment because operators may not realize the skill can create services, read local skills, write persistent state, and expose them over HTTP.
