Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill describes capabilities to read/write files, access the network, and execute shell-driven workflows, yet it does not declare permissions. That creates a transparency and governance gap: operators may enable or trust the skill without understanding its effective access, which is especially risky because it can generate and run test scripts, invoke external APIs, and manipulate persistent data.
