Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documents executable capabilities including environment-variable access, file read/write, shell usage, and network access, yet it declares no permissions. That gap weakens review and consent boundaries because a host system or user may underestimate what the skill can do, especially since it also includes commands that process local files and call external APIs. In this context, the issue is more dangerous because the skill is designed to handle uploads, downloads, and local media operations, so undeclared capabilities materially expand the attack surface.
