Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions, yet its documented workflow clearly requires shell execution, reading credential/config files, and writing generated artifacts such as YAML, tfvars, and Terraform state. This mismatch is dangerous because it hides the skill's real capabilities from any permission-gating or review process, increasing the chance that a user or platform authorizes actions without understanding that the skill can access secrets and modify local infrastructure files.
