Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions while instructing use of environment credentials and local shell-capable tooling such as Python scripts and `dig`. This creates a trust-boundary problem: an agent or user may load the skill assuming it is passive documentation, when it actually expects access to secrets and command execution, increasing the chance of unintended credential exposure or command execution without proper review.
