Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents shell execution, config reads/writes, and access to environment-backed secrets, but does not declare corresponding permissions. This creates a trust and policy bypass problem: reviewers and runtime controls may underestimate what the skill can do, while the skill handles highly sensitive API credentials and modifies persistent configuration.
