Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises executable capabilities including environment access, file read/write, network, and shell, yet declares no permissions. This reduces transparency and prevents users or a runtime policy layer from understanding or constraining what the skill can do, which is risky because the referenced scripts can install packages, access files, and make outbound requests.
