Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation advertises command execution and file/network-related capabilities but does not declare corresponding permissions. This creates a transparency and trust problem: users may invoke the skill without realizing it can read/write local files, access environment variables, and make outbound network requests, which can expose project data or secrets.
