Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes local Python scripts, reads reference files, writes persistent state in cron mode, and likely performs network access to query GitHub releases, yet it declares no permissions. This mismatch is dangerous because it obscures the skill's actual capabilities from reviewers and runtime policy enforcement, increasing the risk of unintended file, environment, or network access without explicit approval.
