Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions, yet its documented behavior and runtime requirements indicate access to environment variables, local files, shell execution, and network resources. This is dangerous because it hides the real privilege footprint from reviewers and policy enforcement, making it easier for a seemingly narrow procurement skill to access secrets, write local state, and invoke external services without transparent authorization.
