Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises no declared permissions, yet the documented commands and described helper behavior imply shell execution, filesystem reads/writes, environment access, and network communication. This creates a transparency and consent gap: a caller may invoke the skill expecting a narrow image-edit capability while it can also persist credentials locally and contact external services. In a skill ecosystem, undeclared capabilities materially increase risk because users and policy layers cannot accurately gate or review what the skill can do.
