Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill declares only `exec` in metadata while its documented behavior and static capabilities indicate file access, network access, shell/process use, and possible environment access. This undermines permission transparency and can cause a host to grant execution to a skill that also reads local files and sends data externally, increasing the chance of unintended data exposure or privilege abuse.
