Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill performs shell execution, reads environment/config files, and makes network calls, but it does not declare equivalent permissions up front. In an agent setting, undeclared capabilities reduce transparency and can bypass operator expectations about what the skill is allowed to access or transmit.
