Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises and demonstrates capabilities that require environment access, filesystem reads/writes, network calls, and shell execution, yet no permissions are declared. That creates a transparency and consent gap: users may invoke the skill expecting a documentation-only migration assistant while it can access local files, process media, call remote APIs, and run local commands such as Python or ffmpeg. In an agent ecosystem, undeclared sensitive capabilities increase the risk of unintended data exposure, secret handling mistakes, and unsafe command execution.
