Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to perform network access, shell execution, environment-variable access, and file reads/writes, yet it declares no corresponding permissions. This creates a transparency and policy-enforcement gap: an agent or platform may execute capabilities users did not explicitly authorize, including writing `.env` files and sending queries/API keys to a remote service.
