Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares access to sensitive environment variables and performs authenticated network operations against a live Magento store, but the finding indicates these capabilities are not explicitly declared as permissions. That creates a governance and least-privilege gap: an agent may be allowed to use the skill without users or platforms clearly understanding it can read secrets and make privileged API calls to production systems.
