Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises no declared permissions, yet its documented usage clearly exercises network access, shell execution, environment access via $SKILL_PATH, and local file write capability when storing credentials with 0600 permissions. This creates a trust and review gap: users or policy engines may approve the skill under the false assumption that it is low-privilege, while it can actually make outbound requests and persist secrets locally.
