Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes executable capabilities including shell execution, network access, local file read/write, and environment/config handling, but it does not declare permissions or present a clear capability boundary in a machine-enforceable way. This is dangerous because users or hosting agents may invoke the skill with broader access than expected, increasing the chance of unintended file exposure, command execution, or outbound data transfer.
