Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill exposes code-capable behavior including environment access, file read/write, shell execution, and network use, but does not declare permissions or clearly scope those capabilities. This is dangerous because callers and reviewers cannot accurately assess what the skill may access or modify, increasing the risk of unintended data exposure, filesystem changes, command execution, or outbound transfer of sensitive material such as local media and API credentials.
