Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes effective capabilities for environment access, filesystem I/O, shell execution, and network calls without declaring permissions or clearly constraining their use. This is dangerous because users and reviewers cannot accurately assess what the skill may access or execute, increasing the risk of secret exposure, unintended file modification, or arbitrary external requests if supporting scripts are invoked.
