Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions, yet its documented behavior clearly includes reading environment secrets, accessing files under the user's home directory, writing configuration data, and making network requests. This is dangerous because the host or user may authorize the skill under incomplete assumptions, preventing informed consent and weakening sandboxing or policy enforcement.
