Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation clearly instructs use of shell commands, browser automation, and local file writes, but the manifest does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: users or orchestrators may invoke a skill believing it is lower-privilege than it actually is, increasing the chance of unintended file access or command execution.
