Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation advertises filesystem and network behavior but does not declare permissions accordingly. This is dangerous because users or hosting platforms may assume the skill is local-only while it can read/write under the home directory and fetch remote archives, weakening consent and sandboxing expectations.
