Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill performs network access, reads environment variables, and references file operations, but it does not declare any permissions or capability boundaries. In an agent setting, this creates a transparency and governance problem because the skill can transmit credentials and modify remote content without an explicit permission model visible to users or orchestrators.
