Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes capabilities that require environment access, file read/write, network access, and shell execution, but it declares no permissions. This creates a transparency and trust problem: a user or hosting platform may invoke the skill without understanding that it can read local files, persist secrets, call remote APIs, and launch commands, increasing the risk of unintended data exposure or unsafe execution paths.
