Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises no explicit permissions, yet the documentation clearly describes capabilities involving shell execution, file reads/writes, environment-variable access, and optional network use. That mismatch is dangerous because it prevents hosts or users from making an informed trust decision and can lead to over-privileged execution of a skill that modifies local files and invokes external endpoints.
