Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares required binaries and environment variables, but there is no explicit permissions declaration despite capabilities that can read secrets from the environment and write files. This weakens the trust boundary for agents and reviewers because the skill can handle credentials and produce artifacts without a clear, machine-readable permission contract.
