Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises executable capabilities involving environment access, filesystem operations, networking, and shell usage but declares no permissions. This creates a trust and sandboxing gap: operators and users cannot accurately assess what the skill may access, and a permissive runtime could allow unintended data exposure, external calls, or local command execution without explicit review.
