Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill exercises sensitive capabilities including network access, environment-variable configuration, and Markdown file read/write operations, but it does not declare permissions. That creates a transparency and governance gap: users and the host agent may invoke a skill that can modify files or access external services without an explicit capability contract. In this context the risk is real because the workflow explicitly supports arbitrary --file paths and external HTTP quote/search calls, increasing the chance of unintended file modification or data egress if the skill is misused or integrated into a broader agent pipeline.
