Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill advertises only a guard/confirmation role, but the documentation clearly indicates capabilities spanning file read/write, shell, and network operations without any declared permission model. Undeclared powerful capabilities make review, sandboxing, and user consent much weaker, especially for a persistent resident skill intended to intercept sensitive operations.
