Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises no declared permissions while the implementation reportedly uses environment access, network access, and shell-like capabilities. This creates a transparency and consent problem: operators may install or trust the skill without understanding it can inspect local state, communicate externally, or invoke system-level behavior. In a multi-agent management context, undeclared capabilities are especially risky because the tool may have access to many agents, local workspaces, and sensitive configuration data.
