Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation describes capabilities that access environment variables, write files, make network requests, and invoke shell tooling, yet it declares no permissions. This weakens user awareness and platform policy enforcement, making it easier for the skill to perform sensitive actions without explicit consent or review. The context increases risk because it saves content locally and uses third-party fetch services, so hidden capabilities directly affect privacy and integrity.
