Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no permissions, yet the specification clearly relies on environment access (`ACCESS_KEY`), file reads/writes (`.env`, configuration), and network calls to backend services and telemetry endpoints. This mismatch is dangerous because reviewers and policy engines may treat the skill as lower-risk than it actually is, weakening consent, sandboxing, and monitoring controls.
