Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs access to environment variables and local files such as AGENTS.md, but the skill manifest does not declare those capabilities. Undeclared capability use reduces transparency and informed consent, making it easier for a skill to access configuration and contextual data without clear permission boundaries.
