Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs scanning files, reading environment data, writing credential stores, and invoking shell commands, yet it declares no permissions. That mismatch undermines review and consent because users cannot accurately assess the skill's operational reach before using it.
