Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation advertises capabilities that require access to environment variables, local files, shell execution, and outbound network access, but it does not declare permissions or boundaries for those operations. This creates a real security issue because agents or users may run the skill without understanding its privilege requirements, increasing the risk of unintended secret exposure, unsafe command execution, or broader filesystem/network access than expected.
