Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill metadata declares required binaries and environment variables but does not declare any explicit permissions despite clearly instructing shell execution and authenticated network access. In an agent ecosystem, that mismatch weakens policy enforcement and informed consent because the runtime may grant broader capabilities than users expect.
