Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill exposes operational capabilities including environment access, file read/write, network, and shell execution through documented commands, but does not declare permissions. This creates a trust and review gap: users or orchestrators may treat the skill as low-privilege while it can install packages, access local files, and make outbound requests, increasing the risk of unintended data exposure or command execution if the skill is invoked in a sensitive environment.
