Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation clearly instructs use of file access, shell execution, and outbound network access, but no declared permissions are shown. That mismatch is dangerous because users and hosting frameworks cannot accurately understand or constrain the skill's capabilities, increasing the risk of unintended data access, command execution, or external transmission.
