Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises shell execution, file access, environment access, and network use without declaring permissions, which undermines least-privilege expectations and makes the operational risk opaque to users and reviewers. In this context, the commands install packages and run a Python helper that can read/write local data and contact external services, so undeclared capabilities could enable unintended data exposure or unsafe execution paths.
