Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises environment and network-capable behavior but does not declare permissions, which undermines auditability and informed consent. In a self-modifying/evolutionary skill, hidden access to env vars and networking materially increases the chance of secret exposure, remote command channels, or unreviewed outbound publication.
