Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and documents shell execution, environment-variable use, network access, and local file read/write behaviors, but no explicit permissions are declared. That creates a transparency and consent gap: users may invoke code that uploads media, stores config under the home directory, or downloads results locally without a clearly declared capability boundary. In this context, the risk is elevated because the skill is positioned as planning/search-operations assistance, yet it also drives operational automation touching credentials, files, and remote APIs.
