Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes capabilities that require environment access, file reads/writes, and network use, but it does not declare permissions or provide an explicit trust boundary for those operations. This can cause agents or users to run setup and model-download flows without understanding that the skill will create environments, install packages, write model artifacts, and fetch remote dependencies, increasing supply-chain and local file-system risk.
