Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises capabilities to read/write local credentials, use environment variables, make network calls, and invoke shell-adjacent helper scripts, but the finding indicates these capabilities are not formally declared in permissions. That mismatch weakens reviewability and consent boundaries: operators may underestimate what the skill can do, especially since it handles secrets and can launch a browser or related helper tooling.
