Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documents file read/write and shell-based workflows but does not declare corresponding permissions, which weakens user awareness and any policy enforcement built around explicit capability declarations. In a credential-management skill, undeclared filesystem and shell access is especially sensitive because it handles secrets and writes session material to disk.
