Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill declares no permissions while explicitly documenting capabilities that read local data, consume environment variables, execute shell commands, and send content to an external API. This is dangerous because users and host platforms cannot accurately assess or gate the real trust boundary, especially for an always-on hook that may process sensitive conversation history automatically.
