Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and documents capabilities that access environment variables, read/write local files, use the network, and invoke shell commands, yet it declares no permissions. This creates a trust and containment gap: users or the host platform may invoke the skill without understanding it can store API keys locally, upload local media, download outputs, and run subprocesses, increasing the chance of unintended data exposure or over-privileged execution.
