Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill invokes commands that package workspace state, upload/download files, and handle encryption material, but the manifest declares no permissions. This under-disclosure is dangerous because users or orchestrators may authorize and invoke the skill without understanding that it can access environment-derived state and perform broad persistence actions.
