Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the user to run shell commands, install a Python package, read local reference files, write outputs, use environment variables like SKILL_PATH, and send data to a remote API, but it declares no permissions. This mismatch is dangerous because it hides the true execution and data-handling capabilities of the skill, preventing informed review of filesystem, shell, and network exposure.
