Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill requests execution of local shell commands, reads environment variables, and performs networked operations, yet declares itself as a simple read-only IAM query skill without corresponding permission disclosure. This is dangerous because users or orchestrators may authorize the skill under a lower-trust assumption while it can bootstrap environments, access credentials, and reach external resources.
