Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises capabilities that imply access to environment variables, network communication, and shell execution, yet declares no corresponding permissions. This creates a trust and sandboxing gap: users and hosts may under-estimate the skill's reach, while the documented startup flow and optional LLM integration show realistic paths to local process execution and outbound requests. In a memory-oriented skill handling sensitive conversations, undeclared capabilities materially increase risk.
