Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs the model to read environment configuration, persist user-supplied API keys, and call remote services, but no explicit permissions are declared. This creates a hidden capability surface where the agent can access local state, write secrets, and make network requests without transparent consent boundaries, which is especially risky given the misleading skill identity.
