Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises executable capabilities including shell, network, environment access, and local file read/write, yet no permissions are explicitly declared. This creates an authorization transparency gap: users and hosting platforms cannot accurately assess or constrain what the skill may do, increasing the chance of unintended secret access, local file modification, or network misuse.
