Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill requires powerful capabilities—environment access for credentials, network access to Amazon endpoints, and file write for report output—but does not declare any permissions. Even though these capabilities are expected for an SP-API wrapper, the missing declaration weakens user visibility and policy enforcement, and could allow secret-bearing operations or file writes to occur without explicit approval boundaries.
