Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and documents capabilities including environment-variable access, local file read/write, network access, and shell execution, but does not declare permissions or provide a least-privilege boundary. This creates a transparency and consent problem: users may invoke a skill that can access credentials, local files, and the network without explicit permission disclosure, increasing the risk of unintended data exposure or abuse if the underlying script is modified or misused.
