Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill requires shell, network, environment-variable, and local file capabilities to operate, but it does not declare permissions or otherwise constrain those powers in a machine-readable way. That creates a confused-deputy risk where an agent or platform may invoke a networked, command-executing skill without clear sandboxing or user awareness, especially because it handles an authentication token and performs state-changing remote actions.
