Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises substantial capabilities—network access, file read/write, shell execution, and environment access—but does not declare permissions. This creates a transparency and governance gap: operators and users cannot reliably assess what the skill may access, making it easier for a misconfigured or compromised implementation to exceed expected trust boundaries.
