Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions, yet the documented commands and behavior clearly imply shell execution, file access, environment variable use, network access, and local state/config writes. This is dangerous because users and policy systems cannot accurately assess or constrain what the skill can do, creating hidden attack surface and weakening least-privilege enforcement.
