Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises no declared permissions, yet its documented behavior includes shell execution, file read/write, environment access, and network communication. This creates a transparency and trust problem: users or enforcement systems may approve the skill under a lower-risk assumption while it can still handle API keys, write local artifacts, and make outbound requests.
