Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly describes reading local files, extracting and caching a DLL payload, consulting environment variables, and later reading candidate JSONL logs. Those are real capabilities, but the metadata shown here does not declare corresponding permissions, which weakens reviewability and user consent and can enable unexpected access to local data. In this context the capability is aligned with the stated purpose, so the issue is under-declaration rather than clearly malicious behavior.
