Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documents capabilities to read environment variables, read/write local files, use sqlite, and make outbound network requests, but it does not declare permissions explicitly. That creates a transparency and policy-enforcement gap: an agent or reviewer may assume the skill is less privileged than it really is, while the skill can still persist data locally and contact external services. In a security-sensitive agent environment, undeclared capabilities increase the chance of unauthorized data access, persistence, or exfiltration through normal-looking analysis flows.
