Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no explicit permissions, yet its own description and usage clearly rely on web research, content fetching, GIF lookup, and invoking the `grizzly` CLI, which implies network access, shell execution, and likely environment/tool access. This mismatch weakens trust boundaries and reviewability because consumers may approve the skill believing it is lower-privilege than it actually is, increasing the chance of unintended data access or command execution in an agent context.
