Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises executable behavior involving environment access, shell execution, file reads/writes, and network calls, but does not declare permissions or clearly scope those capabilities. This creates a trust gap: users may invoke the skill without understanding it can read local inputs, store config/results, and contact a remote API, increasing the risk of unintended data exposure or unsafe execution in agent environments.
