Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill exposes significant capabilities—shell execution, network access, file read/write, and environment variable use—without declaring permissions or clearly constraining how those powers are used. In an agent setting, this weakens transparency and policy enforcement, making it easier for the skill to access secrets like DINGTALK_WEBHOOK, modify local files, and run external commands in ways a caller may not expect.
