Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises only outline generation, but the detected capabilities include environment access, file read/write, and network use without any declared permissions. That creates a trust and review gap: operators may approve or run the skill without realizing it can exfiltrate local project data or secrets via outbound requests.
