Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions, yet the documented workflow clearly involves shell execution, file writes, and network access. This is dangerous because users and policy layers cannot accurately assess or constrain what the skill will do before execution, increasing the chance of unexpected local modification or outbound connections.
