Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares substantial capabilities in its documentation and usage flow—environment variable access, local file read/write, network access, and shell execution—yet no explicit permissions are declared. This creates a transparency and consent gap: users or orchestration systems may invoke a skill with broader access than expected, including auto-installing packages and accessing credentials, which increases abuse and supply-chain risk.
