Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes shell commands, reads user-supplied files, writes output files, uses environment variables for API keys, and sends data over the network, yet it declares no permissions or trust boundaries. This is dangerous because it hides powerful capabilities from the host/user and prevents informed consent, especially when the data being processed is highly sensitive family chat content.
