Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and implies capabilities to access environment variables, write files, perform network requests, and invoke shell/system tools, yet it declares no permissions or safety boundaries. This creates a trust and review gap: an agent or user may invoke a skill that can modify cron/configuration state or send network traffic without explicit authorization, increasing the chance of unintended system changes or secret exposure.
