Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation describes capabilities to read environment variables, read/write local files, invoke shell commands, and access the network, but it does not declare permissions or present a bounded permission model. This can mislead users and orchestration systems about the skill’s effective authority, increasing the risk of silent data access, local file modification, or unintended external communications when the skill is invoked.
