Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation exposes executable capabilities including shell, network, filesystem access, and environment use, but does not declare permissions or constrain them in a machine-readable way. This creates a trust gap where an agent may invoke code that can read local files, write outputs, or call external services without clear user awareness or policy enforcement, increasing the risk of unintended data exposure or unsafe execution.
