Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises and instructs use of local scripts and external tooling that imply shell execution, file reads, environment access, and possible network use, yet it declares no permissions or capability boundaries. This mismatch can cause reviewers or runtime policy systems to underestimate what the skill may do, increasing the risk of unintended execution, data exposure, or overbroad trust during evaluation.
