Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill exposes shell, filesystem, environment, and network-capable workflows in documentation without declaring corresponding permissions. This creates a transparency and trust-boundary problem: a user or platform may invoke the skill believing it is narrowly scoped, while the referenced scripts can access local files, environment secrets, and remote services. In this context, the danger is increased because the skill claims a simple background-replacement purpose but operationally depends on a generic script entrypoint with broader capabilities.
