Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill explicitly describes access to environment-derived paths and runtime-dependent filesystem behavior via `process.env.USERPROFILE || process.env.HOME`, yet no permissions are declared. In an orchestration skill that spawns agents, reads configuration, and writes outputs, missing permission declarations weaken reviewability and can cause the skill to operate with broader implicit capabilities than users expect.
