Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares only `read` and `exec`, but the document also describes capabilities that imply broader access such as reading memory logs, environment/runtime constraints, and file-based storage interactions. This kind of permission/capability mismatch is dangerous because it obscures the real trust boundary, making reviewers and users underestimate what data the skill may access or how it operates.
