Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill describes capabilities to read environment variables, write local files, and make outbound network requests, but does not declare any permissions or equivalent trust boundary information. This can mislead operators about the skill's actual access and increases the chance it is run in an overly permissive or insufficiently reviewed context.
