Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no permissions even though it clearly instructs shell execution, file reads, and file writes. In a wallet-management context, undeclared capabilities are especially risky because they conceal the ability to install software, modify local state, and handle secrets, weakening user and platform trust boundaries.
