Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to invoke shell commands, use a browser-backed network scraper, and access host-mounted storage, but it does not declare permissions up front. That mismatch is dangerous because users and policy layers may not understand the skill's true capabilities, reducing informed consent and weakening guardrails around filesystem, network, and command execution.
