Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read local code/docs and reference an external documentation site, while the static analyzer also inferred broader capabilities such as file access, environment access, and network use. Because no permissions are declared, operators and downstream enforcement layers may underestimate what the skill can access or trigger, which creates a governance and containment gap if the bundled implementation or surrounding runtime actually exposes those capabilities.
