Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares no permissions, yet its documented commands and referenced script imply capabilities including shell execution, filesystem access, environment access, and network use. This is dangerous because users and platforms may trust the skill as low-privilege while it can install packages, read local inputs, write config/state, and contact external services, expanding the attack surface and enabling data exposure or unexpected side effects.
