Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill declares no permissions while its documented behavior and referenced scripts imply network access, shell execution, and likely environment/file access. This mismatch weakens user consent and sandboxing because operators may run a skill with broader capabilities than disclosed, increasing the chance of unintended external communication or local data exposure.
